To keep your system secure, change known passwords for user profiles and dedicated service tools.
User ID | Password | Recommended value |
---|---|---|
QSECOFR | QSECOFR1 | A nontrivial value known only to the security administrator. Write down the password that you have selected and store it in a safe place. |
QSYSOPR | QSYSOPR | *NONE2 |
QPGMR | QPGMR | *NONE2 |
QUSER | QUSER | *NONE2, 3 |
QSRV | QSRV | *NONE2 |
QSRVBAS | QSRVBAS | *NONE2 |
Note:
|
DST Level | User ID1 | Password | Recommended Value |
---|---|---|---|
Basic capability | 11111111 | 11111111 | A nontrivial value known only to the security administrator.2 |
Full capability | 22222222 | 222222223 | A nontrivial value known only to the security administrator.2 |
Security capability | QSECOFR | QSECOFR3 | A nontrivial value known only to the security administrator.2 |
Service capability | QSRV | QSRV3 | A nontrivial value known only to the security administrator.2 |
Note:
|
You also can use system service tools (SST) instead of DST to change passwords.
You can manage and create service tools user IDs from system service tools (SST) by selecting option 8 (Work with service tools user IDs) from the main SST display. You no longer need to go into DST to reset passwords, grant or revoke privileges, or create service tools user IDs.
The server is shipped with limited ability to change default and expired passwords. This means that you cannot change service tools user IDs that have default and expired passwords through the Change Service Tools User ID (QSYCHGDS) API, nor can you change their passwords through SST. You can only change a service tools user ID with a default and expired password through DST. You can change the setting to allow default and expired passwords to be changed. Also, you can use the new Start service tools (STRSST) privilege to create a service tools user ID that can access DST, but can be restricted from accessing SST.
If you need to sign on with one of the IBM-supplied profiles, you can change the password using the CHGUSRPRF command. You can also change these passwords using an option from the SETUP menu. To protect your system, you should leave the password set to *NONE for all IBM-supplied profiles except QSECOFR. Do not allow trivial passwords for the QSECOFR profile.
Change Passwords for IBM-Supplied Profiles Type new password below for IBM-supplied user, type password again to verify change, then press Enter. New security officer (QSECOFR) password . . . . . . New password (to verify) . . . . . . . . . . . . . New system operator (QSYSOPR) password . . . . . . . New password (to verify) . . . . . . . . . . . . . New programmer (QPGMR) password . . . . . . . . . . New password (to verify) . . . . . . . . . . . . . New user (QUSER) password . . . . . . . . . . . . . New password (to verify) . . . . . . . . . . . . . New service (QSRV) password . . . . . . . . . . . . New password (to verify) . . . . . . . . . . . . .
Change Passwords for IBM-Supplied Profiles Type new password below for IBM-supplied user, type change, then press Enter. New basic service (QSRVBAS) password . . . . . . . . New password (to verify) . . . . . . . . . . . .