Error Description

Access panel content is displayed when the "isSecAdm" is        
manually changed from false to true in the server response body
when accessing the new Digital Certificate Manager web          
application on port 2006/2007.                                  

Problem Summary

When using a low authority user, it is possible to request the  
DCM UI to display a screen intended for a system administrator  
by setting the "isSecAdm" DCM flag to 'true' on the client.    
With the full menu displayed, the low authority user is able to
click on buttons to send DCM action requests including the      
ability to browse the file system for objects.                  

Problem Conclusion

IBM Digital Certificate Manager for i is designed to be used by
low authority users to download CA certificates into their      
browsers when the user has been given *RX access to the CA      
certificate files.  As such, there are two menus to display    
based on a user's authority.  The full menu is intended for    
users with *ALLOBJ and *SECADM authority, a shorter menu is for
users without those special authorities.  Regardless of which  
menu is presented, the actions that are requested are controlled
by authority checks on IBM i so only the authorized logged in  
user can perform the intended requests via DCM UI.              
The fix which is provided will ensure that users accessing DCM  
are only able to request the actions they are expected to      
perform via the DCM UI.  For users that do not have *ALLOBJ and
*SECADM special authority, any browsing of the file system via  
DCM is prevented.  Attempting to get a list of existing        
certificate stores returns an empty list.  Attempting to perform
actions such as creating a certificate store results in an      
authority error.                                                
These extra controls have been added to the DCM UI to reduce    
actions for users before the authority checks are performed by  
the IBM i operating system.                                    

PTFs Available

R730 SI79582  2335

R740 SI79583  2328

R750 SI79585  2321

Summary Information

Status............................  CLOSED PER
HIPER.............................  No
Component.........................  5770SS1DC
Failing Module....................  RCHMGR
Reported Release..................  R740
02 December 2022