As a coda to Rob's recommendations, you should almost certainly ensure
that those profiles cannot be used to sign on to the system by
specifying (off the top of my head)
INLPGM(*NONE) and INLMNU(*SIGNOFF).
From: MIDRANGE-L [mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of
Sent: Thursday, May 15, 2014 8:32 AM
To: Midrange Systems Technical Discussion
Subject: Re: Audits and profiles with passwords the same as the profile
Whether a user profile owns objects, is in a group, is the group, etc.
should have no effect on whether or not you change the password.
What will have an effect is if you do stuff like have PC RMTCMD
tied to the old password, RUNRMTCMD for IBM i to IBM i communication,
embedded CONNECT TO ... USING statements using the password in the code,
Lotus Enterprise Integrator (or like techniques), java connections,
WRKRDBDIRE and a plethora of other things.
I say change it. It's too big of a security risk. It's worth the
possible disruption in business that may pop up because of imbedded
This mailing list archive is Copyright 1997-2014 by MIDRANGE dot COM and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available here. If you have questions about this, please contact