• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Feeding the Auditor: Taking Care of Problem User Profiles

    September 29, 2010 Hey, Joe

    Help. My iSeries shop is being audited. The auditors want a list of all users who have default passwords. They also want us to automatically disable any user profiles that haven’t been active for 60 days. I don’t want to automatically disable my inactive users because I have a lot of profiles that should never be disabled on our system. How do I handle this? I’m on i/OS V5R4M5.

    –Brett

    Finding your default password users is easy. Simply run the following Analyze Default Password (ANZDFTPWD) command and you’ll get a listing of all system users whose password is equal to their user profile name.

    ANZDFTPWD ACTION(*NONE)
    

    Even though *NONE is the default setting for the Action Taken Against Profiles (ACTION) parameter, I always run this command with ACTION set to *NONE. I do this because ANZDFTPWD can also be set up to either: 1) automatically disable all user profiles with default passwords; or 2) automatically expire the passwords for all default password profiles. If I run the command with an action of *NONE, ANZDFTPWD simply produces a report that I can look at and determine which profiles I need to take action for.

    After you run ANZDFTPWD, you can examine the generated report to help you straighten out any obvious issues that you don’t want the auditors to see. After making adjustments, you can then rerun the report, and give the second report to the auditors.

    As produced, the generated ANZDFTPWD report tells you two things about each default password user profile.

    1. Is the user profile active or disabled (*ENABLED or *DISABLED)?
    2. Is the user profile’s Password Expiration (PWDEXP) parameter set to *YES or *NO?

    The command also issues the following CPC2232 message to your desktop and to your joblog:

    "&1 user profiles have default passwords of which &2 have the status of *ENABLED"
    

    Where parameter 1 (&1) equals the total number of default password users and parameter 2 (&2) is equal to the number of default password users whose user profiles are enabled.

    With this information (total number of active users with default passwords as well as which individual users have active non-expired default passwords), you can respond to the auditors depending on how serious the issue is. If it turns out that the majority of your default password users are disabled or have expired passwords, you may be able to remediate the problem by correcting the remaining user profiles and running ANZDFTPWD a second time. After settling on a course of action, you can run ANZDFTPWD in one of the following two modes.

    ANZDFTPWD ACTION(*PWDEXP)
    

    Or:

    ANZDFTPWD ACTION(*DISABLE)
    

    Running ANZDFTPWD with the ACTION parameter equal to *PWDEXP, sets all the default password user passwords to *EXPIRED, which means that those users will have to change their passwords the next time they sign on, eliminating each user’s default password problem. The second option, where ACTION is set to *DISABLE, disables ALL of your default password users, which can put a number of active users immediately out of commission. I only recommend automatic disablement if the number of active default password users is relatively low and automatically disabling users won’t hinder production or cause a flood of calls to your Help Desk.

    As for automatically disabling any users who haven’t signed on to your system in 60 days, that’s easily doable, but there are a few pitfalls. i/OS offers three commands to help you perform this function.

    • Analyze Profile Activity (ANZPRFACT) sets up a nightly job that automatically disables all user profiles that haven’t been active in the target number of days. This job will not disable any inactive users who are on the i/OS Active Profile List.
    • Display Active Profile List (DSPACTPRFL) shows the Active Profile List, which contains all user profiles that are exempt from being disabled by the ANZPRFACT command. User profiles on the Active Profile list will not be automatically disabled, no matter how long they have been inactive.
    • Change Active Profile List (CHGACTPRFL) allows you to modify the Active Profile List, so that you can protect infrequent users from automatic user profile disablement.

    There are a few ins and outs to using these commands. Before working with the Profile List commands, check out this article on The Joys and Pains of Automatically Disabling User Profiles for more information. But given your requirement for automatically disabling inactive users, these commands can help you meet that goal.

    HTH

    –Joe

    RELATED STORY

    The Joys and Pains of Automatically Disabling User Profiles



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    PowerTech:  FREE Webinar! Reduce the Cost and Effort of IBM i Auditing. Sept. 29, 10 a.m. CT
    LANSA:  2010 iPulse Survey. Taking the pulse of the IBM i market. Get a chance to win an iPad!
    COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Q Software to Widen Market for Security Tools The Little Power7 Engines That Could–And Those That Won’t

    Leave a Reply Cancel reply

Volume 10, Number 29 -- September 29, 2010
THIS ISSUE SPONSORED BY:

WorksRight Software
iSeries DevCon2010
inFORM Decisions

Table of Contents

  • RPG Sorting and Searching: A 7.1 Update
  • CASE Simplifies SQL Update
  • Feeding the Auditor: Taking Care of Problem User Profiles

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle