68 lines
4.6 KiB
HTML
68 lines
4.6 KiB
HTML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE html
|
|
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
|
<html lang="en-us" xml:lang="en-us">
|
|
<head>
|
|
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
|
<meta name="security" content="public" />
|
|
<meta name="Robots" content="index,follow" />
|
|
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
|
|
<meta name="DC.Type" content="reference" />
|
|
<meta name="DC.Title" content="Recommendations for managing service tools user IDs" />
|
|
<meta name="abstract" content="This information provides the recommendations for managing service tools user IDs." />
|
|
<meta name="description" content="This information provides the recommendations for managing service tools user IDs." />
|
|
<meta name="DC.Relation" scheme="URI" content="rzamhmanageuserids.htm" />
|
|
<meta name="DC.Relation" scheme="URI" content="rzamhchguserids.htm" />
|
|
<meta name="DC.Relation" scheme="URI" content="rzamhrecover.htm" />
|
|
<meta name="DC.Relation" scheme="URI" content="rzamhchguserids.htm" />
|
|
<meta name="copyright" content="(C) Copyright IBM Corporation 2003, 2006" />
|
|
<meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 2003, 2006" />
|
|
<meta name="DC.Format" content="XHTML" />
|
|
<meta name="DC.Identifier" content="rzamhrecommendations" />
|
|
<meta name="DC.Language" content="en-us" />
|
|
<!-- All rights reserved. Licensed Materials Property of IBM -->
|
|
<!-- US Government Users Restricted Rights -->
|
|
<!-- Use, duplication or disclosure restricted by -->
|
|
<!-- GSA ADP Schedule Contract with IBM Corp. -->
|
|
<link rel="stylesheet" type="text/css" href="./ibmdita.css" />
|
|
<link rel="stylesheet" type="text/css" href="./ic.css" />
|
|
<title>Recommendations for managing service tools user IDs</title>
|
|
</head>
|
|
<body id="rzamhrecommendations"><a name="rzamhrecommendations"><!-- --></a>
|
|
<!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
|
|
<h1 class="topictitle1">Recommendations for managing service tools user IDs</h1>
|
|
<div><p>This information provides the recommendations for managing service
|
|
tools user IDs.</p>
|
|
<div class="section"><h4 class="sectiontitle">Create your own version of the QSECOFR service tools user
|
|
ID</h4><p>Do not use the IBM-supplied service tools user ID QSECOFR. Instead,
|
|
review what functional privileges are given to QSECOFR and create a duplicate
|
|
user ID with a different name that has the same functional privileges. Use
|
|
this new user ID to manage your other service tools user IDs. This can help
|
|
eliminate the security exposure that originates because QSECOFR is the value
|
|
included in every server and is commonly known.</p>
|
|
<div class="attention"><span class="attentiontitle">Attention:</span> Do
|
|
not leave the QSECOFR service tools user ID and password set to the default
|
|
value. This is a security exposure because this is the value included in every iSeries™ server
|
|
and is commonly known. </div>
|
|
</div>
|
|
<div class="section"><h4 class="sectiontitle">Service tools security functional privilege</h4><p>The <em>Service
|
|
tools security</em> functional privilege is the privilege that allows a service
|
|
tools user ID to create and manage other service tools user IDs. Because
|
|
this is a powerful privilege, only your QSECOFR-equivalent service tools user
|
|
ID should be given this privilege. Give careful consideration to whom you
|
|
grant this functional privilege.</p>
|
|
</div>
|
|
</div>
|
|
<div>
|
|
<div class="familylinks">
|
|
<div class="parentlink"><strong>Parent topic:</strong> <a href="rzamhmanageuserids.htm" title="To develop an effective strategy for managing and maintaining service tools user IDs, you need to configure and change service tools user IDs, recover or reset QSECOFR passwords, and save or restore service tools security data.">Manage service tools user IDs</a></div>
|
|
</div>
|
|
<div class="relconcepts"><strong>Related concepts</strong><br />
|
|
<div><a href="rzamhrecover.htm" title="When IBM ships a server, both a QSECOFR i5/OS user profile and a QSECOFR service tools user ID are supplied. These are not the same. They exist in different locations and are used to access different functions.">Recover or reset QSECOFR passwords</a></div>
|
|
</div>
|
|
<div class="relref"><strong>Related reference</strong><br />
|
|
<div><a href="rzamhchguserids.htm" title="This information explains how to change service tools user IDs and passwords.">Change service tools user IDs and passwords</a></div>
|
|
</div>
|
|
</div>
|
|
</body>
|
|
</html> |