EXTENDED SECURITY field (EXTSEC subsystem parameter)

The EXTSEC subsystem parameter specifies how two related security options are to be set. These settings control what happens when a DDF connection has security errors and whether RACF® users can change their passwords through the DRDA change password function.

Acceptable values: YES, NO
Default: YES
Update: Start of changeoption 31 on panel DSNTIPBEnd of change
DSNZPxxx: DSN6SYSP EXTSEC
Start of changeSubsystem parameter:End of change Start of changeYesEnd of change
YES
Detailed reason codes are returned to a DRDA level 3 client when a DDF connection request fails because of security errors. When using SNA protocols, the requester must have included a product that supports the extended security sense codes. One such product is DB2® Connect.

RACF users can change their passwords by using the DRDA change password function. This support is only for DRDA requesters that have implemented support for changing passwords.

NO
Generic error codes are returned to the clients and RACF users are prevented from changing their passwords.
Recommendation: Specify a value of YES. This setting allows properly enabled DRDA clients to determine the cause of security failures without requiring DB2 operator support. A value of YES also allows RACF users on properly enabled DB2 clients to change their passwords.
Note: Start of changeThis is a security-related parameter. When this parameter is set to YES, detailed reason codes are returned to the client when a DDF connection request fails because of security errors that might enable more malicious attacks. If this parameter is set to YES, RACF users can change their passwords by using the DRDA change password function.End of change