Re: New Password rules at VRM610

"Jones, John (US)" <John.Jones-4kQQZ61tH+/[email protected]> Tue, 22 Apr 2008 08:48:40 -0500
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
I would add that, compared to simply omitting specific characters, the
better solution would be to implement a password validation program that
excludes common words to avoid dictionary attacks.  This is in addition
to the regular password rule system values.

To start, free dictionary word lists in various languages are available
at, um, http://www.word-list.com/. 

-- 
John A. Jones, CISSP
Sr. Analyst, Global Information Security
Jones Lang LaSalle, Inc.
Voice: +1.630-455.2787
FAX: +1.312.601.1782
Email: john.jones-4kQQZ61tH+/[email protected]


-----Original Message-----
From: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
[mailto:security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]] On Behalf Of Leif Svalgaard
Sent: Monday, April 21, 2008 9:24 PM
To: Security Administration on the AS400 / iSeries
Subject: Re: [Security400] New Password rules at VRM610

>  QPWDLMTCHR allows you to force omission of certain characters from
>  passwords (typically vowels) but I cannot see a similar function in
>  the new rules.

And for a very good reason as it is a silly facility to have. Every time
you
remove symbols from key, the key-space gets smaller, thus weakening
the encryption. I guess IBM finally wizened up.


On Mon, Apr 21, 2008 at 9:13 PM, Simon Coulter <shc-Q/[email protected]>
wrote:
>
>  I was looking through the changes for security in VRM610 specifically
>  the new system values for password rules. Essentially the old QPWD*
>  system values directly related to password rules are replaced
>  (supported but obviously deprecated) by a new single system value
>  QPWDRULES that takes multiple values. All-in-all a good idea but I
>  noticed the following anomaly:
>
>         There appears to be no direct replacement for the QPWDLMTCHR
system
>  value.
>
>  QPWDLMTCHR allows you to force omission of certain characters from
>  passwords (typically vowels) but I cannot see a similar function in
>  the new rules.
>
>  Is this simply a documentation oversight?
>  Is QPWDLMTCHR still effective even when using the new method?
>  Have I simply missed something?
>
>  Regards,
>  Simon Coulter.
>  --------------------------------------------------------------------
>     FlyByNight Software         OS/400, i5/OS Technical Specialists
>
>     http://www.flybynight.com.au/
>     Phone: +61 2 6657 8251   Mobile: +61 0411 091 400        /"\
>     Fax:   +61 2 6657 8251                                   \ /
>                                                               X
>                   ASCII Ribbon campaign against HTML E-Mail  / \
>  --------------------------------------------------------------------
>
>
>
>  _______________________________________________
>  This is the Security Administration on the AS400 / iSeries
(Security400) mailing list
>  To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
>  To subscribe, unsubscribe, or change list options,
>  visit: http://lists.midrange.com/mailman/listinfo/security400
>  or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
>  Before posting, please take a moment to review the archives
>  at http://archive.midrange.com/security400.
>
>



-- 
Leif
[email protected]
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400)
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.



This email is for the use of the intended recipient(s) only.  If you have 
received this email in error, please notify the sender immediately and then 
delete it.  If you are not the intended recipient, you must not keep, use, 
disclose, copy or distribute this email without the author's prior 
permission.  We have taken precautions to minimize the risk of transmitting 
software viruses, but we advise you to carry out your own virus checks on 
any attachment to this message.  We cannot accept liability for any loss 
or damage caused by software viruses.  The information contained in this 
communication may be confidential and may be subject to the attorney-client 
privilege. If you are the intended recipient and you do not wish to receive 
similar electronic messages from us in the future then please respond to the 
sender to this effect.

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.