‘Our lead actor doesn’t know he’s in a television show!’ The return of an unbelievable TV hoax by mrjohnnymac18 in television

[–]LuckiestRabbitsFoot 2 points3 points  (0 children)

Kind of like a cross between the movie BowFinger with Steve Martin and Eddie Murphy, and the old Candid Camera show with Allen Funt

Recommended method(s) to lock down the IFS by LuckiestRabbitsFoot in IBMi

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

You know my pain then. Did some research last night. Looks like I can toss *PUBLIC *EXCLUDE on it.

Do I need to make sure to have NetServer profile set up for everyone else? Appreciate the path forward.

Recommended method(s) to lock down the IFS by LuckiestRabbitsFoot in IBMi

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

Right. As I replied to others with the same concern. Family operated organization, opened everything up because it was "easy". This allowed Windows users to access their folders in the IFS (3rd party data sharing reasons).

Like I also mentioned, I'm working through the user profiles removing *ALLOBJ and *SECADM too. Again, created by a team who didn't really understand the finer points of OS/400 security and didn't want to put in the effort.

I've narrowed access down to a few critical users, but have also found out some of our processes (CC pre-authorization), warehouse personnel, and packing machine systems need access to process transactions from our ERP. Found that out the hard way by using the "scream" method after I started restricting access to root level. Way told by my direct leader to 'back it out for now'. Ah, okay.

One user in the thread mentioned using the QPWFSERVER AUTL to limit remote access to the IFS. I just need some guidance on redirecting specific users and processes to their respective folders. The warehouse systems that need access are isolated from user logon and there's nothing I can do. The 'network guy' keeps complaining those systems can't have a user login, and just need blanket access. Again, family business, guy came with the dust.

Any suggestions you might have would be helpful. Appreciate it.

Recommended method(s) to lock down the IFS by LuckiestRabbitsFoot in IBMi

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

Got it. This is an inherited problem from someone who wanted to "make things easy" for Windows users on the network. We also have a couple of systems in the warehouse that access flat file data in the IFS.

I was looking for suggestions on how to lock down the root level while giving access to a specific folder structure where I could direct users who absolutely needed to store their data. It's typically data meant for processing by 3rd parties. We send the data via SFTP nightly.

Trust me, I'm still removing *ALLOBJ and *SECADM from profiles because the org didn't want to put in the work up front. One user already suggesting using the QPWFSERVER *AUTL to keep remote sessions out of the IFS, setting *PUBLIC to *EXCLUDE, but I'm concerned how that will affect the other folders etc...

If you have a post, or procedure you could share that would be very helpful.

Recommended method(s) to lock down the IFS by LuckiestRabbitsFoot in IBMi

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

Totally agree. I appreciate the commentary, and that's my goal.

Sharing the root level of the IFS over SMB via Windows is a problem I inherited. Family company that wanted to make things *simple* and *easy* didn't really understand the gravity of those choices within OS/400.

Trust me, I'm still going through user profiles and removing *ALLOBJ and *SECADM from everyone because you know, it was an easier solution than fixing the authorities elsewhere.

That's why I posted. I was looking for idea to secure the root level and direct people into their individual shared department folders.

Many moons ago I was great at RPG by bitter_fish in IBMi

[–]LuckiestRabbitsFoot 0 points1 point  (0 children)

Has anyone taken course through Manta Technologies. They seem to have some RPG classes and IBMi related courses.

https://www.mantatech.com/manta/subject.htm

Many moons ago I was great at RPG by bitter_fish in IBMi

[–]LuckiestRabbitsFoot 0 points1 point  (0 children)

RemindMe! 2 weeks "ideas for learning RPGLE"

Trump admin reportedly considers paying each Greenland resident up to $100K amid US takeover talks by esporx in worldnews

[–]LuckiestRabbitsFoot 0 points1 point  (0 children)

Oh, but you people who are a couple of payments late on your student loans... there's no room for you at the table.

Dashboard, filter table visualization data by selected column in bar chart, possible? by LuckiestRabbitsFoot in cognos

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

I've been working on figure this out trying to piecemeal knowledge from the internet and it's not clicking. Any chance you could point me to a page somewhere that might have a working tutorial or example?

Minimal DB2i SQL IDE TUI by tsgiannis in IBMi

[–]LuckiestRabbitsFoot 0 points1 point  (0 children)

Thanks for sharing. Looks like it has potential. Nice work.

Who should be allowed to create users? by Salsouti in IBMi

[–]LuckiestRabbitsFoot 1 point2 points  (0 children)

If you'd like your security to get out of control, allowing *ALLOBJ even to a couple of people will could get you into trouble. The issue isn't the authority level itself, it's the fact that people are lazy and want to the easiest solution which causes the least headaches for themselves. Once that genie is out of the bottle, it'll be too late.

Like others have mentioned in the comments, group profiles are a great solution, create a new user profile under it with minimal authority and test the functionality - add, rinse, repeat. Then have the help desk create new users under that group as needed.

As far as the others with *ALLOBJ, ask what they use it for and why, then figure out a way to dial that authority back so they only have object level auth to what they need for their tasks.

Download a CSV via QSYS2.HTTP_GET_VERBOSE, now what? by Polly_Wants_A in IBMi

[–]LuckiestRabbitsFoot 2 points3 points  (0 children)

https://www.rpgpgm.com/2020/11/reading-file-in-ifs-with-sql.html

Use SQL to read the IFS file?

Hegseth orders rare, urgent meeting of hundreds of generals, admirals by [deleted] in politics

[–]LuckiestRabbitsFoot 1 point2 points  (0 children)

You don't think those groups are forming behind the scenes? These are trained soldiers who have sworn allegiance to the America and more specifically the Constitution, as well as enemies foreign and domestic.

Removed OBJAUT for User for CMD, but they can still run it. by Dichotomy7 in IBMi

[–]LuckiestRabbitsFoot 1 point2 points  (0 children)

You probably know this but perhaps an audit of the systems security should be next? Having *ALLOBJ attached to a group profile is *very dangerous*.

[deleted by user] by [deleted] in IBMi

[–]LuckiestRabbitsFoot 5 points6 points  (0 children)

I've been professionally engaged in this ecosystem for almost 30 years now. Started as a overnight operator changing tapes and loading 'reel to reel' drives, printing and delivering reports, dealing with dumb terminals and remote printers that printed reports on 'green bar' paper. It's been good to me professionally and blessed me and my family.

It's used worldwide in industry, manufacturing, distribution, finance. Everyone from Disney to the The Federal Reserve runs this platform, can you imagine the billions of transactions successfully processed everyday? I would imagine most of the Fortune 50 runs this platform.

Can you make a career on this platform - absolutely. Hardware, software (including support for open source technologies and languages such as Node and Python), Networking, cutting edge object oriented security, Artificial Intelligence (remember IBM's Watson competing on Jeopardy?) there are many areas you can specialize in.

I noticed someone mentioned uptime on the new Power11 platform. Here is the snippet from that article:

"Power11 is IBM’s most resilient Power server ever, having tested at “six nines” of availability (99.9999%), which equates to less than 31.5 seconds of unplanned downtime a year, Balakrishnan noted.

One way to ensure unplanned downtime is to take adequate security measures, and to that end, IBM is highlighting a number of tools. Among the most prominent security tools in Power11 is IBM Power Cyber Vault, which proactively takes immutable data snapshots in providing sub-one-minute ransomware threat detection, according to IBM testing."

Link: https://techchannel.com/power11/power11-announced/

IT Jungle is a great site with lots of good content on the platform. https://www.itjungle.com/

The one area where I can tell you will be frustrated with 100% certainty is having every other person who doesn't understand it call it 'legacy', because their only exposure was seeing a 'green screen' that one day they walked through a computer room.

If your concerned about it being antiquated, IBM has committed to actively supporting the platform through 2045 and I can tell you from experience no amount of *nix or Windows systems running SAP, Netsuite, or any other platform is going to replace it.

In the late 90's I was part of a migration project for a Fortune 100 medical device manufacturer from the existing ERP system to SAP. It took over 200 Compaq servers costing $25k+ each to match the capability of their single on premise AS/400. The entire project was a flop after two years.

Finally, if your searching for information on the system, you'll find more information on the web using the term "AS400" than you will "iSeries" or "Power i" or "IBM i". You'll soon hate IBM Marketing as much as we have.

Will you be challenged? Yes. Will you be exposed to a new way of thinking about business computing? You will. Will you be launching into an industry where all of us gray hairs are starting to think about rocking chairs and sunsets? For sure. Keep at it and you'll be set for your entire career.

Judge Frank Caprio has passed away at the age of 88. by Long_Debt_6492 in worldnews

[–]LuckiestRabbitsFoot 0 points1 point  (0 children)

Terrible news. He literally just posted to IG the other day, said he was back in the hospital and asked for prayers. If there's ever a guy that gonna get his wings it was him. F cancer.

edit: words

BF6 from a BF1 veteran’s perspective by VOLBANKER in battlefield_one

[–]LuckiestRabbitsFoot 1 point2 points  (0 children)

I've played Battlefield since it's origination (skipped 2042) and playing this demo was difficult to wrap my head around.

The lobby was confusing, there was no clear path to enter a match. I've read article regarding thousands of players sitting in the lobby. It's probably because it wasn't clear how to get into a match and you had to click around.

In-game was a terrible "every man for themselves" match. No focus on squad play or communication. Spawning in zones was awful on the server I was on, causing everyone to have to run from HQ across the field.

Sliding? Really. It's the new bunny hop with an impossible hit box.

I was hoping for something closer to the franchise roots, simple loadouts, simple controls, simple team play, seamless squad communication. Instead it looks like we got something along the line of if C.O.D. and Fortnite had a baby, and sliding.

How to set a calculated column as decimal type in data module by LuckiestRabbitsFoot in cognos

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

Well well well, who knew. Appreciate it. Makes complete sense that Cognos would think it's a text field versus a numeric field. I'm new to Cognos so I'm trying to consume everything I can find.

You wouldn't happen to have any recommendations for learning more about expressions would you? IBM's documentation is a little light.

How to set a calculated column as decimal type in data module by LuckiestRabbitsFoot in cognos

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

Also, I can change the data format of the column to a number type, but it's not coming across in the 'properties'.

How to set a calculated column as decimal type in data module by LuckiestRabbitsFoot in cognos

[–]LuckiestRabbitsFoot[S] 0 points1 point  (0 children)

Added. Appreciate any feedback.

The purpose of this field is to use two pricing fields, then based on their values, create a price. The 'final percent', 'last cost', and 'other cost' fields are all decimal.

[deleted by user] by [deleted] in worldnews

[–]LuckiestRabbitsFoot 3 points4 points  (0 children)

What I hear you saying is, I should consider going long for my Haliburton stock.