|
| |
Recommendations for managing service tools user IDs
The following are recommendations for managing service tools user IDs.
Create your own version of the QSECOFR service tools user ID
Do not use the IBM-supplied QSECOFR service tools user ID. Instead, review what
functional privileges are given to QSECOFR and create a duplicate user ID with a
different name that has the same functional privileges. See the information in
Change service tools user IDs and passwords for detailed instructions. Use this
new user ID to manage your other service tools user IDs. This will help
eliminate the security exposure that originates because QSECOFR is the value
shipped with every server and is commonly known.
Service tools security functional privilege
The Service tools security functional privilege is the privilege that allows a
service tools user ID to create and manage other service tools user IDs. Since
this is a powerful privilege, only your QSECOFR-equivalent service tools user ID
should be given this privilege. Give careful consideration to whom you grant
this functional privilege.
|