Posted: Thu May 27, 2004 5:55 am Post subject: removing write permission for 'other' in mqm filesystems
Novice
Joined: 27 Apr 2004 Posts: 12
Does anyone see a problem or have experience recursively removing write permission for 'other' on the /usr/mqm and /var/mqm filesystems trees? Our security group is cracking down and would like us to remove write access for 'other'.
Example: /var/mqm/errors and /var/mqm/trace are currently 777 out of the box. I'd like to change them and the files they contain to 775.
Note: This would be in a AIX and Linux environment.
Can you provide an example of what I won't be able to do? I thought /var/mqm/errors was only written to for generating FDC's and for MQClient errors. Aren't both of these written by the userid which started the queue manager, which is in the mqm group and wouldn't fall under the 'other' permissions?
Under what circumstances would a user which is not in the mqm group need write permission on any files in the /var/mqm or /usr/mqm filesystems?
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum