Implementing Single Sign On (SSO) would provide a great solution to this issue. NetServer can be configured for SSO as well as TELNET, ACS and Client Access.
SSO could in fact, eliminate having to store ANY user passwords on the iSeries. Instead of entering a password, a user would authenticate to Active Directory when signing on to their PC and through the use of Kerberos Tickets and EIM, access to the iSeries would then be transparent (no need to provide a user ID or password).
All the user has to do then is manage his regular Windows Active Directory password.
SSO isn't an all or nothing implementation either. Certain user profiles, like QSECOFR and other special system administration User Profiles could still require that a User ID and password be specified to access the system.
Otherwise, it is really necessary (in my experience) to synchronize the PC password with the iSeries password. If that is done, NetServer works just fine. It isn't that hard to set up iSeries password rules that match your PC password rules. There have been a lot of changes to the QPWDRULES System Value over the last few releases.
Reply or Forwarded mail from: Kenneth E Graap
-----Original Message-----
From: MIDRANGE-L [mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of Smith, Mike
Sent: Friday, July 07, 2017 1:41 PM
To: Midrange Systems Technical Discussion (midrange-l@xxxxxxxxxxxx)
Subject: [External]ifs mapped drive issue
I am testing the use of mapped drives to our IFS.
I have set up a shortcut on a Virtual Desktop.
If my network id and ibm I password are the same, I have no issues, If my network id and ibm I ID are different, I have no issues.
However if my network id and my ibm I password are not the same I cannot get connected.
I get a 'Windows Security' prompt to enter user id and password but receive 'Network password is not correct' After a couple attempts at this my Netserver userid becomes disabled.
If I try to use the network password I get 'Access is denied'.
Any idea what might be going on here.
I've done some searching and found some references to the issue, but no resolutions.
THanks
NOTICE: This message, including any attachment, is intended as a confidential and privileged communication. If you have received this message in error, or are not the named recipient(s), please immediately notify the sender and delete this message.
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options,
visit:
http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at
http://archive.midrange.com/midrange-l.
Please contact support@xxxxxxxxxxxx for any subscription related questions.
Help support midrange.com by shopping at amazon.com with our affiliate link:
http://amzn.to/2dEadiD
As an Amazon Associate we earn from qualifying purchases.