Re: New Password rules at VRM610

[email protected] Tue, 22 Apr 2008 13:42:01 -0400
Newsgroups gmane.comp.systems.as400.security
Message-ID <OFAD662F93.C7B31009-ON85257433.0060D61F-85257433.00613B69@dekko.com>
Simon,

Limiting characters was a good way to forbid words.  Taking out vowels was 
a common technique.  Removing this capability does not do much for 
"freedom of choice" for administrators.

However, from a V6R1 machine:

Message ID . . . . . . :   CPF22C5  
Date sent  . . . . . . :   04/22/08      Time sent  . . . . . . : 13:41:14 

  
Message . . . . :   Password contains one of the following: A.  
  
Cause . . . . . :   The password rule for restricted characters in 
passwords 
  (system value QPWDLMTCHR) requires that they not contain any of the  
  following characters: A.  
Recovery  . . . :   Specify a new password that does not contain any of 
the 
  restricted characters.  


Rob Berendt
-- 
Group Dekko Services, LLC
Dept 01.073
Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com





Simon Coulter <shc-Q/[email protected]> 
Sent by: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
04/21/2008 10:14 PM
Please respond to
Security Administration on the AS400 / iSeries  <security400-Zwy7GipZuJhWk0Htik3J/[email protected]>


To
Security Administration on the AS400 / iSeries <security400-Zwy7GipZuJhWk0Htik3J/[email protected]>
cc

Subject
[Security400] New Password rules at VRM610







I was looking through the changes for security in VRM610 specifically 
the new system values for password rules. Essentially the old QPWD* 
system values directly related to password rules are replaced 
(supported but obviously deprecated) by a new single system value 
QPWDRULES that takes multiple values. All-in-all a good idea but I 
noticed the following anomaly:

                 There appears to be no direct replacement for the 
QPWDLMTCHR system 
value.

QPWDLMTCHR allows you to force omission of certain characters from 
passwords (typically vowels) but I cannot see a similar function in 
the new rules.

Is this simply a documentation oversight?
Is QPWDLMTCHR still effective even when using the new method?
Have I simply missed something?

Regards,
Simon Coulter.
--------------------------------------------------------------------
    FlyByNight Software         OS/400, i5/OS Technical Specialists

    http://www.flybynight.com.au/
    Phone: +61 2 6657 8251   Mobile: +61 0411 091 400        /"\
    Fax:   +61 2 6657 8251                                   \ /
                                                              X
                  ASCII Ribbon campaign against HTML E-Mail  / \
--------------------------------------------------------------------



_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) 
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.


_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.