Where allowed to run: All environments (*ALL) Threadsafe: No |
Parameters Examples Error messages |
The Change Network Server User Attributes (CHGNWSUSRA) command is used to change network server attributes for an i5/OS user or group profile that operate in a networking environment. This command can be used to do the following:
When an i5/OS user is enrolled, a matching Windows user identity is created in the Windows domain or on the Windows local server.
When an i5/OS group profile is enrolled into a Windows domain or local server, a matching Windows group is created in the domain or local server. All i5/OS user profiles that are defined in the group are enrolled into the domain or local server and added to the Windows groups that are currently defined by the user account template.
Network server user attributes are saved by the Save System (SAVSYS) and Save Security Data (SAVSECDTA) commands. Network server user attributes are restored to the system when the user profile is restored. The Restore User Profiles (RSTUSRPRF) command can be used to restore user profiles and the network server user attributes associated with them.
Restrictions:
Top |
Keyword | Description | Choices | Notes |
---|---|---|---|
USRPRF | User profile | Simple name, *CURRENT | Optional, Key, Positional 1 |
PRFTYPE | Profile type | *USER, *GROUP | Optional, Key, Positional 2 |
PMTCTL | Prompt control | *ALL, *WINDOWS, *NETWARE, *WINDOWSNT | Optional, Key, Positional 3 |
PRPGRPMBR | Propagate group members | *SAME, *NONE, *ALL, *MBRONLY | Optional |
DFTSVRTYPE | Default server type | *SAME, *WINDOWS, *NWSA, *NETWARE, *WINDOWSNT | Optional |
NDSTREE | NDS tree | Character value, *SAME, *NWSA, *NONE | Optional |
NDSCTX | NDS context | Path name, *SAME, *NWSA, *ROOT | Optional |
NDSTREELST | NDS tree list | Single values: *SAME, *NWSA, *NONE Other values (up to 10 repetitions): Element list |
Optional |
Element 1: NDS tree | Character value | ||
Element 2: User object context | Path name | ||
Element 3: Default server | Character value, *ANY | ||
Element 4: Profile object | Path name, *NONE | ||
WNTDMNLST | Windows server domain list | Single values: *SAME, *NWSA, *NONE Other values (up to 64 repetitions): Element list |
Optional |
Element 1: Domain | Character value | ||
Element 2: User template | Character value, *NONE | ||
Element 3: Group type | *GLOBAL, *LOCAL | ||
WNTLCLSVRL | Windows local server list | Single values: *SAME, *NWSA, *NONE Other values (up to 64 repetitions): Element list |
Optional |
Element 1: Server | Character value | ||
Element 2: User template | Character value, *NONE |
Top |
Specifies the name of an i5/OS user profile whose network server attributes are to be set.
The following IBM-supplied objects are not valid on this parameter:
QAUTPRF QNFSANON QYCMCIMOM QCOLSRV QRJE QEJBSVR QDBSHR QSNADS QSRVAGT QDBSHRDO QSPL QANZAGENT QDFTOWN QSPLJOB QIBMHELP QDOC QSYS QDSNX QTCP QEJB QTFTP QFNC QTSTRQS QGATE QCLUMGT QLPAUTO QTCM QLPINSTALL QIPP QMSF QPM400 QNETSPLF QNTP QYPSJSVR QCLUSTER QNETWARE * QMGTC
* QNETWARE is legal to enroll if it is a user on a NetWare tree or server. Any other use of QNETWARE is not supported.
The following profile names are not valid on this parameter when enrolling to a Windows domain or server.
GUEST GUESTS REPLICATOR USERS
Note that QAUTPRF and QNFSANON were not disallowed in versions earlier than V4R1. Also, profiles QPRJOWN, QSRV, QSRVBAS, QSVSM, QTMPLPD, and QUMB were disallowed in pre-V4R1 versions, but are now legal to enroll. The change was made in order to keep in sync with the list of objects that i5/OS security uses for some commands.
Top |
Specifies whether the user or group attributes for a profile are to be changed.
Top |
Specifies which network server attributes should be prompted for on the command.
Note: *WINDOWS should be used in V5R4 and later releases. The *WINDOWSNT value is supported for compatibility with releases prior to V5R4.
Top |
Specifies how an i5/OS group and its users are to be enrolled. There are two different ways that an i5/OS group and its users can be enrolled.
Top |
Specifies the default server type for this user. This attribute is used primarily as a default for those i5/OS commands that support multiple network types.
Note: *WINDOWS should be used in V5R4 and later releases. The *WINDOWSNT value is supported for compatibility with releases prior to V5R4.
Top |
Specifies the name of the default NetWare Directory Services tree used by this user. The tree specified should be the one most often used by this i5/OS user when accessing the network.
Top |
Specifies the complete path name of a default NetWare Directory Services context, associated with the tree specified by the NDSTREE parameter, to be used when this user issues i5/OS commands that use NDS objects. This becomes the current context when the i5/OS user signs on.
Top |
Specifies a default list of NetWare Directory Services trees that will be used by the iSeries network administration support to determine which NetWare v4.x trees to enroll this i5/OS profile to. Each entry in the list will contain an NDS tree name and a list of default attributes associated with that tree.
Up to 10 entries can be specified for this parameter. An entry consists of a value from each of the following elements.
Single values
Element 1: NDS tree
Element 2: User object context
Specifies the location in the NDS tree where newly created NDS user objects are created when enrolling profiles into the NDS tree. If the user object already exits in the NDS tree, it will be moved to this context the first time the iSeries administration support attempts to enroll the i5/OS profile. The NetWare complete name must be specified for this element.
Element 3: Default server
Specifies the default NetWare Directory Services server to be used by the system when enrolling profiles into the NDS tree.
Element 4: Profile object
Specifies a default NetWare Directory Services profile object that contains the profile login script to be used by the user when logging into the network. The NetWare distinguished name must be specified for this element.
Top |
Specifies a list of Windows domains that will be used by the i5/OS user enrollment support to determine into which Windows domains this i5/OS profile is enrolled.
Each entry in the list will contain a domain, a user account template name, and a group type. The user account template name is the name of a Windows user identity that is to be used when creating new Windows users.
Up to 64 entries can be specified for this parameter. An entry consists of a value from each of the following elements. A domain name must be entered for each entry and must be unique within the list.
If the WNTDMNLST parameter has never been set, it is defaulted to *NONE.
Single values
Element 1: Domain
Element 2: User template
Specifies the name of a Windows user that can be used as a template when creating new Windows users in the Windows domain.
Note: Changing this value will not affect Windows users that are already enrolled in the domain.
Element 3: Group type
Specifies the type of group to be created in the Windows domain. This element is ignored when PRFTYPE(*USER) is specified.
Top |
Specifies a list of Windows local servers that will be used by the i5/OS user enrollment support to determine into which Windows local server the i5/OS profile is enrolled. Only those server names associated with locally configured Integrated xSeries Servers can be specified in this list.
Each entry in the list will contain a server name and associated user account template name. The user account template name is the Windows user account to be used when creating new Windows user identities on the server.
Up to 64 entries can be specified for this parameter. An entry consists of a value from each of the following elements. A server name must be entered for each entry and must be unique within the list.
If the WNTLCLSVRL parameter has never been set, it is defaulted to *NONE.
Single values
Element 1: Server
Element 2: User template
Specifies the name of a Windows user that can be used as a template when creating new Windows users on the local server.
Note: Changing this value will not affect Windows users that are already enrolled on the server.
Top |
Example 1: Enrolling a user into a Windows network
CHGNWSUSRA USRPRF(BOB) DFTSVRTYPE(*WINDOWS) WNTDMNLST((DMN01 USRTMP1) (DMN02 *NONE)) WNTLCLSVRL((LCLSVR1 TMPL1) (LCLSRV2 *NONE))
The above command will change the network server user attributes for user profile BOB. BOB's default server type is set to *WINDOWS.
The i5/OS user enrollment support will enroll user BOB into domain DMN01 using user account template USRTMP1 and also into domain DMN02.
The i5/OS user enrollment support will also enroll user BOB into local server LCLSVR1 using user account template TMPL1 and also into local server LCLSRV2.
Example 2: Enrolling a user into a NetWare network
CHGNWSUSRA USRPRF(DENNIS) NDSTREE(NWTREE1) NDSCTX(.MARKETING.HDQTRS.IBM) NDSTREELST(*NWSA) NTW3SVRLST(NTW3SVR2 NTW3SVR3)
The above command will change the network server user attributes for user profile DENNIS. The default NDS tree will be set to NWTREE1 and the default context to MARKETING.HDQTRS.IBM.
The NDS tree list from the system network server attributes is used. The i5/OS user enrollment support will enroll user DENNIS into each tree specified in the tree list. The NetWare 3.12 server list is set to include servers NTW3SVR2 and NTW3SVR3. User DENNIS will also be enrolled into both of these servers.
Top |
*ESCAPE Messages
Top |