|
||
|
SecureMyi.com Security and Systems Management Newsletter for the IBM i
December 11, 2013 - Vol 3, Issue 40
|
||
|
||
|
Feature Article
|
|
In This Issue
Quick Links
Our Newsletter Sponsors
Platinum Sponsor |
IBM i Security ResourcesIBM i Security Videos - SecureMyi RedBook - Security Guide IBM i
|
|
|
|
|
Security Shorts -
By Dan Riehl The System Value QINACTITV allows you to specify the amount of time (in minutes) that a job may be inactive before the system initiates an action against the offending job. The associated System value, QINACTMSGQ determines the action that is performed. Typically, the action taken is to terminate or disconnect the inactive job, resulting in the workstation display of the log-on screen which requires a re-entry of UserID and Password. It is a good security practice, to specify a time-out value of 60 minutes or less. A signed-on workstation left unattended for any period of time presents a security risk from intruders that would take advantage of a signed-on session. We should protect our systems from this potential unauthorized workstation access. But there are some specifics about the QINACTITV System Value that are often not understood. For example, if you are signed-on to an active workstation session and then, from that session, initiate a workstation session to another system, as in TELNET, or Display Station Pass-thru, the local interactive job will not be considered as inactive. FTP is another example, in which, the QINACTITV value is not considered. In order to control the time-out value for FTP you use the command CHGFTPA(Change FTP Attributes) and specify the time-out value on the INACTTIMO parameter. If you use the System Request key to start an additional interactive job from the same workstation, an action on one session will keep both sessions from being affected by the QINACTITV value. Any action key will cause activity to be registered to the interactive workstation session, thereby marking the session as active. Action keys are keys like ENTER, PageUp/Down, Function Keys, and Help. QINACTITV "30 Minutes" Really Means "Up to 60 Minutes"AND, did you know that if the QINACTITV system value contains the value 30 minutes, a job may not actually be considered inactive for up to an hour? The job that monitors for inactive jobs comes alive at the interval specified in the system value. Here is the relevant quote about this issue from the IBM Information Center. "When the system is started, it checks for inactive jobs at the interval specified by the QINACTITV system value. For example, if the system is started at 9:46 in the morning and the QINACTITV system value is 30 minutes, it checks for inactive jobs at 10:16, 10:46, 11:16, and so on. If it discovers a job that has been inactive for 30 minutes or more, it takes the action specified by the QINACTMSGQ system value. In this example, if a job becomes inactive at 10:17, it will not be acted on until 11:16. At the 10:46 check, it has been inactive for only 29 minutes." |
Sponsored Links
IBM i, iSeries and AS/400
|
|
|
||
|
||
|
Send your IBM i Security and Systems Management News and Events! Send your Questions, Comments, Tips and Stories Copyright 2013 - SecureMyi.com, all rights reserved SecureMyi.com | St Louis MO 63017 |
||