IBM Support

Service Tools Security Enhancements

News


Abstract

The Service Tools CL commands Create Service Tools User ID (CRTSSTUSR), Change Service Tools User ID (CHGSSTUSR), and Change SST Security Attributes (CHGSSTSECA) have been enhanced.
A new SST security attribute was added to indicate whether password exit programs can be added or removed from the QIBM_QSY_VLD_PASSWRD and QIBM_QSY_CHK_PASSWRD exit points.

Content

You are in: IBM i Technology Updates >  IBM i Security  > Service Tools Security Enhancements
Enhancements have been made to these SST commands used for user ID management and configuration:
  • The "Password expiration interval" attribute was added to the Create Service Tools User ID (CRTSSTUSR), Change Service Tools User ID (CHGSSTUSR), and Display Service Tools User ID (DSPSSTUSR). This attribute allows the password expiration interval for an SST user to be set to a different value than the SST password expiration interval security attribute.
  • The following SST attributes were added to the Change SST Security Attributes (CHGSSTSECA) and Display SST Security Attributes (DSPSSTSECA) commands:
    • Duplicate password control
    • Allow add of digital certificates
    • Allow service tools user ID with default and expired password to change its own password
    • Maximum sign-on attempts
    • Password expiration interval
    • Allow add and remove of password exit programs (new)
  • The remaining attributes continue to be managed in SST. The new SST attribute “Allow add and remove of password exit programs” controls whether new exit programs are allowed to be added to, or existing exit programs are allowed to be removed from, the QIBM_QSY_VLD_PASSWRD and QIBM_QSY_CHK_PASSWRD exit points.
For more information, see the CHGSSTSECA command description and CHGSSTUSR command description in IBM Documentation.

[{"Type":"MASTER","Line of Business":{"code":"LOB57","label":"Power"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"ARM Category":[{"code":"a8m0z0000000C4BAAU","label":"IBM i"}],"Platform":[{"code":"PF012","label":"IBM i"}],"Version":"7.5.0"}]

Document Information

Modified date:
03 May 2022

UID

ibm16578661