Elaine Beal wrote:

>We have a non-expiring password that we've used for years and somehow failed 
>the other night. I reset with an alu line command but the new password doesn't 
>work. When I go through the panels it says the current password isn't valid.
>We have changed password rules but I don't see where that matters. I set the 
>new password to existing rules and do not get any errors on the alu.

There are many reasons why that non-expiring psw failed like these possible 
reasons:

The id was unused for x days.
Someone entered an invalid password or if that id was used in a FTP script, 
incorrect password was used.

There are different ways to reset an id:

ALU <id> RESUME - remove revoke attribute, but leave psw unchanged.
ALU <id> PASSWORD(???) - give a TEMPORARY password. The id needs to enter the 
TEMP psw and then the new psw [twice].
ALU <id> PASSWORD(???) NOEXPIRED - That password can be used just as you give 
it. Of course your password rules applies.

Or any combination of above ALU and other keywords you used.

Of course, do you have the right access to reset that id? (Group scope, System 
Special or relevant IRR.??? profile in FACILITY class)

Please post your ICH408I messages when that id failed to log on. 

Also post your ALU command and keywords used. You can mask out actual id and 
psw before posting on IBM-MAIN.

Can you see any SMF records why your ALU failed?

Alternatively, go over to RACF-L for guidance from real RACF gurus.

Groete / Greetings
Elardus Engelbrecht

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

Reply via email to