Keith Smith wrote:

>It has been stated that every RACF ID must have a password.

Statement is correct. From RACF Command Language Ref: AU command:

Every user that you assign a password phrase must have a password. When you 
specify PHRASE for a user without specifying PASSWORD, the user is assigned the 
default password. In your case, it is SYS1.

>I was able to logon to TSO using the password phrase. So, it does not seem to 
>be true that a password is required unless RACF created some random password, 
>but the bottom line is there is no password that I can use to logon except the 
>password phrase.

True, you can use either password or password phrase to logon. But you can 
still logon with password only, just use the group as your password. To avoid 
this exposure always enter a password value and never tell your users what the 
password is.

>  DEFAULT-GROUP=SYS1     PASSDATE=00.000 PASS-INTERVAL= 90
> PHRASEDATE=13.079
> ATTRIBUTES=PASSPHRASE

Now I know your passsssssssssssssssssssssword! It is SYS1 ;-D

Groete / Greetings
Elardus Engelbrecht

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

Reply via email to