TCP/IP commands

This table lists the specific authorities required for the TCP/IP commands.

Commands identified by (Q) are shipped with public authority *EXCLUDE. Commands shipped with public authority *EXCLUDE shows which IBM-supplied user profiles are authorized to the command. The security officer can grant *USE authority to others.

Command Referenced object Authority needed
For object For library
ADDTCPSVR1 Program to call *EXECUTE *EXECUTE
CHGTCPSVR1 Program to call *EXECUTE *EXECUTE
CPYTCPHT 6 File objects    
CVTTCPCL (Q) File objects *USE *EXECUTE
ENDTCPPTP Line description4 *USE *EXECUTE
Controller description4 *USE *EXECUTE
Device description4 *USE *EXECUTE
File objects *USE *EXECUTE
ENDTCPSRV (Q) File objects *USE *EXECUTE
FTP File objects *USE *EXECUTE
Table objects *USE *EXECUTE
LPR 2 Workstation customizing object *USE *EXECUTE
Start of changeRTVTCPINF7 (Q)End of change Start of changeSpecified libraryEnd of change Start of change*READ, *ADD, *EXECUTEEnd of change  
SETVTTBL Table objects *USE *EXECUTE
SNDTCPSPLF 2 Workstation customizing object *USE *EXECUTE
STRTCPFTP Table objects *USE *EXECUTE
File objects *USE *EXECUTE
STRTCPPTP Line description4 *USE *EXECUTE
Controller description4 *USE *EXECUTE
Device description4 *USE *EXECUTE
File Objects *USE *EXECUTE
STRTCPSVR (Q) Table objects *USE *EXECUTE
File objects *USE *EXECUTE
STRTCPTELN Table objects *USE *EXECUTE
File objects *USE *EXECUTE
Virtual workstation device5 *USE *EXECUTE
TELNET Table objects *USE *EXECUTE
File objects *USE *EXECUTE
Virtual workstation device5 *USE *EXECUTE
Start of changeUPDTCPINF8 (Q)End of change Start of changeSpecified libraryEnd of change Start of change*READ, *ADD, *EXECUTEEnd of change  
These commands do not require any object authorities:
ADDCOMSNMP 1
ADDNETTBLE 1
ADDOSPFARA1
ADDOSPFLNK1
ADDOSPFIFC1
ADDOSPFRNG1
ADDPCLTBLE 1
ADDRIPACP1
ADDRIPFLT1
ADDRIPIFC1
ADDRIPIGN1
ADDSRVTBLE 1
ADDTCPHTE 1
ADDTCPIFC 1
ADDTCPPORT 1
ADDTCPRSI 1
ADDTCPRTE 1
Start of changeADDUSRSMTP9End of change
ADDUSRSNMP1
CFGTCP
CFGTCPAPP
CFGTCPFTP 1
CFGTCPLPD 1
CFGRTG
CFGTCPSMTP
CFGTCPSNMP
CFGTCPTELN
CHGCOMSNMP 1
CHGDHCPSVR1
CHGFTPA 1
CHGLPDA 1
CHGOSPFA1
CHGOSPFARA1
CHGOSPFIFC1
CHGOSPFLNK1
CHGOSPFRNG1
CHGRIPA1
CHGRIPFLT1
CHGRIPIFC1
CHGSMTPA 1
CHGSNMPA 1
CHGTCPA 1
CHGTCPHTE1
CHGTCPIFC1
CHGTCPRTE 1
CHGTELNA 1
Start of changeCHGUSRSMTP9End of change
CHGUSRSNMP1
CHGVTMAP

Start of changeCPYVPNCFGF1End of change
DSPVTMAP
ENDTCP (Q)
Start of changeENDVPNCNN1End of change
ENDTCPCNN
ENDTCPIFC (Q)
Start of changeLODIPFTR1End of change
MGRTCPHT 1
NETSTAT
PING
RMVCOMSNMP 1
RMVNETTBLE 1
RMVOSPFARA1
RMVOSPFIFC1
RMVOSPFLNK1
RMVOSPFRNG1
RMVPCLTBLE 1
RMVRIPACP1
RMVRIPFLT1
RMVRIPIFC1
RMVRIPIGN1
RMVSRVTBLE 1
RMVTCPHTE1
RMVTCPIFC1
RMVTCPPORT 1
RMVTCPRSI 1
RMVTCPRTE 1
RMVTCPSVR 1
Start of changeRMVUSRSMTP9End of change
RMVUSRSNMP1
RNMTCPHTE 1
SETVTMAP
Start of changeSNDSMTPEMM10End of change
Start of changeSTRIMPSMTPEnd of change
STRTCP (Q)
STRTCPIFC (Q)

Start of changeSTRVPNCNN1End of change
VFYTCPCNN
WRKNAMSMTP 3
WRKNETTBLE1
WRKPCLTBLE1
Start of changeWRKSMTPEMM1End of change
Start of changeWRKSMTPUSR9End of change
WRKSRVTBLE1
WRKTCPSTS
1
You must have *IOSYSCFG special authority to use this command.
2
The SNDTCPSPLF command and the LPR command use the same combinations of referenced object authorities as the SNDNETSPLF command.
3
You must have *SECADM special authority to change the system alias table or another user profile's alias table.
4
If you have *JOBCTL special authority, you do not need the specified authority to the object.
5
If you have *JOBCTL special authority, you do not need the specified authority to the object on the remote system.
6
For the required authorities, refer to the description of the Display (DSP) or other operation using output file (OUTPUT(*OUTFILE)) section in the General rules for object authorities on commands topic.
Start of change7End of change
Start of changeYou must have *SAVSYS special authority to use this command.End of change
Start of change8End of change
Start of changeYou must have *ALLOBJ, *SECADM, and *SAVSYS special authorities to use this command.End of change
Start of change9End of change
Start of changeYou must have *SECADM special authority to add, change, remove, or view entries for profiles different than the current user.End of change
Start of change10End of change
Start of changeThe current user profile must be enrolled in the e-mail directory that is set by the CHGSMTPA command and the DIRTYPE keyword. For a setting of *SDD for the DIRTYPE keyword the current user profile must be enrolled in the System Distribution Directory (SDD) and must also have an smtp name defined via the WRKNAMSMTP command. For a setting of *SMTP or *SMTPMSF the current user profile must be enrolled via ADDUSRSMTP.End of change