Password policies for service tools user IDs

This topic describes the password policies for service tools user IDs and the process of changing Data Encryption Standard (DES) and Secure Hash Algorithm (SHA) encryption.

Note: Multiple incorrect password attempts to sign on will disable the service tools user ID. If that occurs, you can sign on with the disabled user ID from the console, and then reset the user ID.

Service tools user IDs are separate from i5/OS™ user profiles. Passwords for service tools user IDs are encrypted at different levels for security. The default password level uses DES encryption. You should use DES encryption if you have pre-V5R1 clients using iSeries™ Navigator to connect to service functions such as logical partitions and disk unit management.

You can change the password level to use SHA encryption, which is mathematically impossible to reverse and provides stronger encryption and a higher level of security. If you change to SHA encryption, however, you cannot change back to DES encryption. Also, if you change to SHA encryption, you can no longer connect to the service tools server with pre-V5R1 clients, such as Operations Console. When you upgrade your password level to SHA, you need to upgrade any clients that use these functions.

DES encryption

When you use DES encryption, service tools user IDs and passwords have the following characteristics:

SHA encryption

When you use SHA encryption, service tools user IDs and passwords have the following characteristics:

To change to use SHA encryption, access DST and perform the following steps:

  1. Sign on to DST using your service tools user ID. The Use dedicated service tools (DST) display appears.
  2. Select option 5 (Work with DST environment) and press Enter. The Work with DST Environment display appears.
  3. Select option 6 (Service tools security data) and press Enter.
  4. Select option 6 (Password level) and press Enter. Press Enter again if you are ready to go to the new password level.
Related concepts
Access service tools using DST
Change service tools user IDs and passwords using STRSST or Change Service Tools User ID (QSYCHGDS) API
Recover or reset QSECOFR passwords
Related tasks
Change service tools user IDs and passwords using DST
Change service tools user IDs and passwords using SST
Related reference
Service tools user IDs