home *** CD-ROM | disk | FTP | other *** search
- Comments: Gated by NETNEWS@AUVM.AMERICAN.EDU
- Path: sparky!uunet!europa.asd.contel.com!paladin.american.edu!auvm!USCMVSA.BITNET!LDW
- Message-ID: <IBM-MAIN%92111121325117@RICEVM1.RICE.EDU>
- Newsgroups: bit.listserv.ibm-main
- Date: Wed, 11 Nov 1992 19:29:00 PST
- Sender: IBM Mainframe Discussion list <IBM-MAIN@RICEVM1.BITNET>
- From: Leonard D Woren <LDW@USCMVSA.BITNET>
- Subject: Re: Using IKJTSO00 for authorized pgms
- Lines: 13
-
- On Wed, 11 Nov 1992 13:18:25 EST, SOMITCW@VCCSCENT.BITNET said:
- > ...
- > 3. Put the program in SYS1.PARMLIB(IKJTSO00) under AUTHCMD, AUTHPGM,
- > or AUTHTSF as needed or all three to be safe.
-
- I would recommend against that. In particular, don't put *anything*
- in AUTHTSF that wasn't specifically coded with security in mind, and
- the intent that it would be invoked via TSR. Otherwise you may have
- a security exposure. This is why AUTHTSF was separated out from
- AUTHPGM a few years ago. I will not describe the security exposure
- here.
-
- /Leonard
-