Limit device sessions

The limit device sessions system value specifies whether a user is allowed to be signed on to more than one device at a time.

This value does not restrict the System Request menu or a second signon from the same device. If a user has a disconnected job, the user is allowed to sign on to the system with a new device session. Allowing users to sign on to only one workstation at a time promotes good security habits. If you limit users to one device, you discourage users from sharing user IDs and passwords. If people share user IDs, you lose both control and accountability. You can no longer tell who really does what functions on the system. In addition users must remember to sign off one workstation before moving to another one. Workstations left signed on, but not in use, pose a security risk. Give every system user a unique user ID and password with the appropriate authorities, then restrict them to using one workstation at a time. You can also restrict users to a specific device through individual user profiles.

See Table 2 table for an overview of the limit device sessions system value.

Table 1. Possible values for the limit device sessions system value
iSeries™ Navigator Character-based interface Description
Deselected 0 (No) The system allows an unlimited number of signon sessions.
Selected 1 (Yes) Users are limited to one device session.

Relationship to security policy

Setting the limit device sessions system value discourages sharing password and leaving workstation signed on; however, regardless of the decision you make for this system value, your security policy should implicitly discourage these practices. These bad habits provide a potential attacker access to your resources and sensitive business information. In your security policy users should be made aware of the risks and the consequences for these practices.

Table 2. Quick Reference. Provides details for the limit device sessions system value.
iSeries Navigator name Limit each user to one device session
Character-based interface name QLMTDEVSSN
Authority

All object access (*ALLOBJ)
Security administrator (*SECADM)

Note: The Security Officer (QSECOFR) user profile is shipped with these authorities.
How to access
iSeries Navigator
  1. Expand Security > Policies.
  2. Right click Signon Policy and select Properties.
  3. On the General page, you will find the option for limiting device sessions.
Character-based interface
  1. In the character-based interface, type WRKSYSVAL QLMTDEVSSN.
Changes take effect Immediately
Default value Deselected
Recommended value Selected
Lockable Yes
Special considerations NA

For more detailed information about this security value, see Chapter 3, "Security System Values" in Security Reference.