Add/Change User Rules

How to Get There

Enter option 2 on the Exit Point Manager Main Menu to display the Work with Security by User panel. Press F2 to display the Add User Rules panel.

What it Does

The Global Rule Facility panel allows you to create user rules for all Servers.

These rules will have a Function of *ALL.

Options

System

System indicates the target of any operations you perform. When you add rules, for example, those rules will be sent to, and will affect processing on, the System named.

User Type

This field is used to indicate whether the associated User field refers to an O/S user profile or a Exit Point Manager User Group.

Valid values are:

U The associated User field refers to an O/S user profile.
G The associated User field refers to a Exit Point Manager user group.
User

User represents the identity of the person initiating a transaction as a user profile.

The special value *PUBLIC, when used on a rule, means that the rule applies to any User lacking a specific rule. when used as a subset or selection parameter, *PUBLIC means to select all such rules for display or printing.

If the associated User Type is a 'G', User represents a Exit Point Manager User Group.

Server

A Server in Exit Point Manager is a controlled entry point into your system. These entry points are determined and defined by IBM. Exit Point Manager has assigned easy-to-remember names to these controlled entry points.

Function

A Function, or Server Function, in Exit Point Manager represents a class of operations that a given Server may perform. For example, the *SIGNON Server classifies its operations as those pertaining to changing passwords, generating authentication tokens, and retrieving signon information. Exit Point Manager has assigned easy-to-remember names to these Functions, such as CHGPWD, GENAUTTKN and RETRIEVE.

Authority Property

The authority assigned for servers and their functions.

Possible values are:

*OS400Exit Point Manager will use normal OS/400 authority for the location. This is valid for both location and user.
*REJECTExit Point Manager will reject requests for the specified location. This is valid for both location and user.
*SWITCHExit Point Manager will use the authority of the switch profile for the specified location. A switch profile entry is required. This is valid for both location and user.
*MEMREJECT Check Memorized Transactions (MTR) for authority. If no MTR authority is encountered, Exit Point Manager will reject requests for the specified location. This is valid for both location and user.
*MEMOS4OO Check Memorized Transactions (MTR) for authority. If no MTR authority is encountered, Exit Point Manager will use normal OS/400 authority for the location. This is valid for both location and user.
*MEMSWITCH Check Memorized Transactions (MTR) for authority. If no MTR authority is encountered, Exit Point Manager will use the authority of the switch profile for the specified location. A switch profile entry is required. This is valid for both location and user.
*SRVFCNExit Point Manager will use the authority defined for the server/function. This is valid for both location and user.
Switch

The Switch profile holds the name of a user profile whose authority is used to process the transaction instead of the authority of the User initiating the transaction. The transaction is executed as, and uses the authority of, this Switch profile.

The job that processes the transaction continues to run under this switch profile until Exit Point Manager processes another transaction request for that job.

Switch profile is allowed only when Authority contains *SWITCH or *MEMSWITCH, if *MEMSWITCH is allowed. Otherwise it must contain *NONE.

Audit Property

The audit property controls the type of requests Exit Point Manager will log.

Possible values are:

* Use the audit value for the server/function.
Y Log all requests by the location/server/function.
N Only log authority failures for the location/server/function.

Exit Point Manager will not change the existing settings and will not create new rules when the All Servers option is taken. This is valid for both location and user.

Message

The message property entry will determine if Exit Point Manager sends a message to the Exit Point Manager message queue.

Possible values are:

* Use the audit value for the server/function.
Y A message is sent to the Exit Point Manager message queue.
N No message is sent.
Capture

Capture transactions for Memorized Transaction Request (MTR).

Possible values are:

* Use the audit value for the server/function.
Y Capture transactions.
N Do not capture transactions.
Change existing

The Change existing option controls whether any existing rules are updated or not updated.

The valid values are Y and N.

Change only

If this is set to 'N' then new rules are added and (depending on the setting for Replace) existing rules are changed.

If this is set to 'Y' then only existing rules are changed.

The valid values are Y and N.

Command Keys

F3 (Exit): Exit the panel without processing any pending changes.

F12 (Cancel) Exit the panel without processing any pending changes.