Values set by the Configure System Security command

This table lists the system values that are set when you run the CFGSYSSEC command. The CFGSYSSEC command runs a program that is called QSYS/QSECCFGS.

Values set by the CFGSYSSEC command

Table 1. Values set by the CFGSYSSEC command
System value names Setting System value description
QALWOBJRST *NONE Whether system state programs and programs that adopt authority can be restored
QAUTOCFG 0 (No) Automatic configuration of new devices
QAUTOVRT 0 The number of virtual device descriptions that the system will automatically create if no device is available for use.
QDEVRCYACN *DSCMSG (Disconnect with message) System action when communications is re-established
QDSCJOBITV 120 Time period before the system takes action on a disconnected job
QDSPSGNINF 1 (Yes) Whether users see the sign-on information display
QINACTITV 60 Time period before the system takes action on an inactive interactive job
QINACTMSGQ *ENDJOB Action that the system takes for an inactive job
QLMTDEVSSN 1 (Yes) Whether users are limited to signing on at one device at a time
QLMTSECOFR 1 (Yes) Whether *ALLOBJ and *SERVICE users are limited to specific devices
QMAXSIGN 3 How many consecutive, unsuccessful sign-on attempts are allowed
QMAXSGNACN 3 (Both) Whether the system disables the workstation or the user profile when the QMAXSIGN limit is reached.
QRMTSIGN *FRCSIGNON How the system handles a remote (pass-through or TELNET) sign-on attempt.
QRMTSVRATR 0 (Off) Allows the system to be analyzed remotely.
QSECURITY 50 The level of security that is enforced
QVFYOBJRST 3 (Verify signatures on restore) Verify object on restore
QPWDEXPITV 60 How often users must change their passwords
QPWDMINLEN 6 Minimum length for passwords
QPWDMAXLEN 8 Maximum length for passwords
QPWDPOSDIF 1 (Yes) Whether every position in a new password must differ from the same position in the last password
QPWDLMTCHR   Characters that are not allowed in passwords
QPWDLMTAJC 1 (Yes) Whether adjacent numbers are prohibited in passwords
QPWDLMTREP 2 (Cannot be repeated consecutively) Whether repeating characters in are prohibited in passwords
QPWDRQDDGT 1 (Yes) Whether passwords must have at least one number
QPWDRQDDIF 1 (32 unique passwords) How many unique passwords are required before a password can be repeated
QPWDVLDPGM *NONE The user exit program that the system calls to validate passwords
Note:
  1. The restricted characters are stored in message ID CPXB302 in the message file QSYS/QCPFMSG. They are shipped as AEIOU@$#. You can use the Change Message Description (CHGMSGD) command to change the restricted characters. The QPWDLMTCHR system value is not enforced at password levels 2 or 3.
The CFGSYSSEC command also sets the password to *NONE for the following IBM-supplied user profiles:
  • QSYSOPR
  • QPGMR
  • QUSER
  • QSRV
  • QSRVBAS
Finally, the CFGSYSSEC command sets up security auditing using the Change Security Auditing (CHGSECAUD) command. The CFGSYSSEC command turns on action and object auditing and also, specifies the default set of actions to audit on the CHGSECAUD command.