After installing cumulative PTF package C5276310 for V3R1, our users couldn't change their passwords. The password validation program we wrote expected three parameters, but PTF SF24770 results in four parameters being passed to the program specified in the system value QPWDVLDPGM. The user profile name is passed along with the new password, the current password, and a return code.
For some people, this won't cause a problem. However, we read that, for security reasons, we should test the number of parameters passed and allow only three. When the password validation program sensed four parameters being passed, it started failing all password tests.
The cover letter for the PTF lets you know about the change, but the documentation for the cumulative package doesn't say a thing about it. Be prepared for unanticipated changes when you install a PTF package.
- Vincent van Steen
LATEST COMMENTS
MC Press Online