fhg
Volume 10, Number 28 -- September 22, 2010

Changing i/OS Password Expiration Settings

Published: September 22, 2010

Hey, Joe:

We found a number of user profiles on our i/OS box that have password expiration intervals of *NOMAX, meaning that their passwords will never expire. We're changing their expiration interval to *SYSVAL, so that each user profile takes its password expiration interval from the global system value. How long after I make this change will the users be required to change their passwords? I'm on i/OS V5R4M5.

--Joe


Before I get to the solution, it's worth reviewing how the password expiration interval is calculated for an IBM iSeries, System i, or Power i user on an i/OS V5R4Mx partition.

1. On your i/OS system, there is a Password Expiration Interval (QPWDEXPITV) system value that serves as a global password expiration interval. This interval specifies the number of days it takes since the last time the user password was changed for the password expiration process to begin. Once the user profile reaches its expiration date less seven days, the user will start receiving warnings that his password is about to expire and the system will offer to let him change the password but a password change is not mandatory. Once the user profile reaches its password expiration date, the user must change his password before he can sign on again.

QPWDEXPITV's shipping value is *NOMAX, which means that in the absence of any user profile overrides, all user passwords will never expire. However, best practices specify that your global password expiration value should be set to 90 days or less, meaning the system will force the user to change his password at least four times a year. Also note that no auditor will recommend that you keep QPWDEXPITV at its default value.

To double-check your QPWDEXPITV value, run this Work with System Value (WRKSYSVAL) command on your system and take option 5=Display.

DSPSYSVAL SYSVAL(QPWDEXPITV)

If QPWDEXPITV equals *NOMAX, I highly recommend that you change it to 90 days or less.

2. Besides the global QPWDEXPITV value, each user profile also contains its own Password Expiration Interval parameter (PWDEXPITV). PWDEXPITV can be set to one of three values. In all three cases, the system will start asking the user to change his password when the expiration date is within seven days of the current date.

  • An individual number of days that the password will expire after it was last changed (between 1 and 366 days). The date the password was last changed is stored with the user profile, and the system then calculates the password expiration date as the last password change date plus the number of days listed here.
  • *SYSVAL--The user profile will take its password expiration interval from the QPWDEXPITV system value. The expiration date is then calculated by adding the number of days in the QPWDEXPITV system value to the last password change date.
  • *NOMAX, which specifies that the user profile password will never expire, which is the situation you are looking to change for your users.

You can view an individual's password expiration value and last changed date by running the following Work with User Profile (WRKUSRPRF) command and select option 5=Display.

WRKUSRPRF USRPRF(user_name)

You can also find this information by looking in the Capabilities tab under the user profile in iSeries Navigator. Here's what that screen looks like.



For our example, let's assume your QPWDEXPITV value is set to 90 days.

If you change a user profile's PWDEXPITV parameter from *NOMAX to *SYSVAL, your users will probably have to change their password the next time they sign in. System-initiated password changes are dependent on the last time the user changed their password, regardless of whether their PWDEXPITV parameter was set to *NOMAX or *SYSVAL at the time. If the user changed their password within the last 90 days (our default password expiration interval), they will not have to start the password change process until 83 days (90 days less seven days) have elapsed.

If the user previously changed their password 83-89 days ago, the system will warn them and ask them if they want to change their password now. If the user changed their password 90+ days ago, then the system will prompt them to change their password immediately. They won't be able to sign on until the password is changed.

Also note that in i/OS V6R1 and i/OS V7R1, IBM has added additional password parameters that will affect your password management. But for a V5R4Mx system, this works as advertised.

--Joe




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
TWIN DATA CORPORATION

Use all your existing Twinax Terminals, Twinax Printers, and other Twinax devices on new System i i5 Power6 & Power5 systems now, and the Power7 when it ships.

Simply connect the Xip Twinax Controller to Ethernet and your Twinax devices to it, and you will be able to use them to connect to your System i (Power6, power5, iSeries or AS/400) over aany Ethernet connection. With the choice of multiple protocols, you can choose what's best for your environment. You can even run IPDS printers without the need to purchase PSF/400 (save approx. $2,500).

The Xip is also the perfect way to upgrade your remote locations to run in any IP environment as well, even over a DSL or Cable Internet connection. Eliminate the costs of Frame Relay networks and any point-to-point phone lines.

Call us for details on the Xip and a 30-day trial:
1-800-597-2525 Domestic
1-908-855-8100 International

www.twindata.com


Senior Technical Editor: Ted Holt
Technical Editor: Joe Hertvik
Contributing Technical Editors: Erwin Earley, Brian Kelly, Michael Sansoterra
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

PowerTech:  FREE Webinar! Reduce the Cost and Effort of IBM i Auditing. Sept. 29, 10 a.m. CT
looksoftware:  RPG OA & Beyond Webinar. Sept 28 & 29. Enter to win an Amazon Kindle™
COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
The More Things Change

Big Sam Is Worried About Oracle--And For Good Reason

Focus Melds Crowdsourced IT Analysis with Social Media

Mad Dog 21/21: Seismically Active Storage

IBM Gives Schools Discounts on Power Systems Iron

Four Hundred Stuff
Pat Townsend Bolsters MFT Lineup with New Encryption Options

Linoma Fleshes Out MFT Line with Reverse Proxy Solution

Consonus Offers Online Backups for IBM i Data

Raz-Lee Bolsters IBM i Security Analysis Tool

IBM Updates Guardium Database Security Software

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
September 4, 2010: Volume 12, Number 36

August 28, 2010: Volume 12, Number 35

August 21, 2010: Volume 12, Number 34

August 14, 2010: Volume 12, Number 33

August 7, 2010: Volume 12, Number 32

July 31, 2010: Volume 12, Number 31

TPM at The Register
Oracle gooses Exadata clusters with chunky Intel chips

Microsoft punts HPC Server 2008 R2

Larry Ellison's first Sparc chip and server

Blade Network adds top-of-racker

IBM ponies up $1.7bn for data warehouse maker

HP tunes blades for Oracle apps

Dell nestles baby Opterons into PowerEdge racks

HP reported close to naming Hurd successor

Ellison: 'We can double Oracle's hardware biz'

Revolution links R stats package to apps

Novell breakup and sale imminent, says report

Cisco to pay divvy in 2011

THIS ISSUE SPONSORED BY:

WorksRight Software
SEQUEL Software
Twin Data Corporation


Printer Friendly Version


TABLE OF CONTENTS
Get Thee to the Web, Part 3

Merge Into the Synchronization Fast Lane with DB2 for i 7.1

Changing i/OS Password Expiration Settings

Four Hundred Guru

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2010 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement