Public authority to the "root" directory

When your system ships, the public authority to the "root" directory is *ALL (all object authorities and all data authorities).

This setting provides flexibility and compatibility with both what UNIX-like applications expect and what typical iSeries™ server users expect. An iSeries server user with command-line capability can create a new library in the QSYS.LIB file system simply by using the CRTLIB command. Normally, authority on a typical iSeries server allows this. Similarly, with the shipped setting for the root file system, a typical user can create a new directory in the root file system (just like you can create a new directory on your PC).

As a security administrator, you must educate your users about adequately protecting the objects that they create. When a user creates a library, probably the public authority to the library should not be *CHANGE, the default value. The user should set public authority either to *USE or to *EXCLUDE, depending on the contents of the library.

If your users need to create new directories in the "root" (/), QOpenSys, or user-defined file systems, you have several security options: