TechTalk: Beware the change made to the password validation program.

Security - Other
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

After installing cumulative PTF package C5276310 for V3R1, our users couldn't change their passwords. The password validation program we wrote expected three parameters, but PTF SF24770 results in four parameters being passed to the program specified in the system value QPWDVLDPGM. The user profile name is passed along with the new password, the current password, and a return code.

For some people, this won't cause a problem. However, we read that, for security reasons, we should test the number of parameters passed and allow only three. When the password validation program sensed four parameters being passed, it started failing all password tests.

The cover letter for the PTF lets you know about the change, but the documentation for the cumulative package doesn't say a thing about it. Be prepared for unanticipated changes when you install a PTF package.

- Vincent van Steen

BLOG COMMENTS POWERED BY DISQUS

LATEST COMMENTS

Support MC Press Online

$

Book Reviews

Resource Center

  •  

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: