Re: Forced password change held to be harmful -- Was RE: RACF password history was: AW: //STARTING JOB ...

2015-01-14 Thread Thomas Berg
A bit OT, but this, I think, is a good idea: http://www.passwordcard.org/en Best Regards, Thomas Berg ___ Thomas Berg Specialist zOS/RQM/IT Delivery Swedbank AB (Publ) -

Re: Forced password change held to be harmful -- Was RE: RACF password history was: AW: //STARTING JOB ...

2015-01-14 Thread Paul Gilmartin
On Wed, 14 Jan 2015 11:15:32 -0500, Hobart Spitz wrote: >Under z/VM, SFS has the capability for a user to have the ability to >grant/revoke access to files and directories that are owned by the user's >id. Thus, users can grant and revoke access to/from their own SFS >resources without the bother

Re: Forced password change held to be harmful -- Was RE: RACF password history was: AW: //STARTING JOB ...

2015-01-14 Thread Hobart Spitz
Under z/VM, SFS has the capability for a user to have the ability to grant/revoke access to files and directories that are owned by the user's id. Thus, users can grant and revoke access to/from their own SFS resources without the bother of involving a security staffer, addressing (1) above. Perh

Re: Forced password change held to be harmful -- Was RE: RACF password history was: AW: //STARTING JOB ...

2015-01-03 Thread Scott Ford
Happy Holidays my friend Regards, Scott From: Charles Mills Sent: ‎Monday‎, ‎December‎ ‎29‎, ‎2014 ‎8‎:‎56‎ ‎AM To: IBM-MAIN@LISTSERV.UA.EDU Why force your users to change passwords at all? I know "everyone does it" but what problems does it solve? 1. Bob needs access to some dataset

Re: Forced password change held to be harmful -- Was RE: RACF password history was: AW: //STARTING JOB ...

2014-12-29 Thread John McKown
On Mon, Dec 29, 2014 at 7:56 AM, Charles Mills wrote: > Why force your users to change passwords at all? I know "everyone does it" > but what problems does it solve? > ​In all truthfullness, for me, the problem it solves is that ​keeps the auditors off my ass. Is that a _good_, technical, reason

Forced password change held to be harmful -- Was RE: RACF password history was: AW: //STARTING JOB ...

2014-12-29 Thread Charles Mills
Why force your users to change passwords at all? I know "everyone does it" but what problems does it solve? 1. Bob needs access to some dataset that his userid does not grant. So Alice loans him her logon credentials. Forcing Alice to change her password prevents Bob from continuing to masquerade