Preventing users from using default passwords

Preventing users from using default passwords

I changed the QOWDRQDDGT to one to eliminate default passwords, but the user's still able to change the password to be the same as the user name. What's happening here? What can I do to ensure that users cannot use default passwords?

    Requires Free Membership to View

    Register today to access targeted resources from our editorial writers and independent industry experts including news, tips, and advice to help you do your job more efficiently and effectively. Stay informed on the hottest topics and biggest challenges faced by IT professionals working with iSeries products and services.

    By submitting your registration information to Search400.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of Search400.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Once you change one of the password composition rule system values (QPWD*), users cannot change their passwords through the Change Password (CHGPWD) command to be a default password (a password the same as the user profile name.) However, if the user has access to the Change User Profile (CHGUSRPRF) command, the password composition rule system values are (intentionally) by-passed and they can set the password to be any password they wish – including a default password. CHGUSRPRF should only be available for use by Administrators whose responsibility is managing profiles.

==================================
MORE INFORMATION ON THIS TOPIC
==================================

The Best Web Links: tips, tutorials and more.

Search400's targeted search engine: Get relevant information on security.

Ask your systems management questions--or help out your peers by answering them--in our live discussion forums.

Check out this Search400.com Featured Topic: Top ten security tips

Visit the ITKnowledge Exchange and get answers to your security questions fast.

This was first published in September 2005