IBM Support

*SECADM Special Authority Is Required to Change QSECOFR Profile

Troubleshooting


Problem

This document provides an option for changing the QSECOFR profile before IPLing to reset the password.

Resolving The Problem

Generally, if the password for the QSECOFR user profile is lost or forgotten, we need to perform a manual IPL and go into DST to reset the password to its original default value. There is an easier method for resetting or changing password for QSECOFR. This method works only if there is another user profile on the system that has *SECADM special authority and object authority to the QSECOFR profile. To search for such user profile, do the following:

1.

From the operating system command line, type the following:

PRTUSRPRF SELECT(*SPCAUT) SPCAUT(*SECADM)

Press the Enter key.
2. On the operating system command line, type the following:

WRKSPLF

Press the Enter key. Find spooled file QPSECUSR, and select Option 5, Display. The display looks similar to the following:

          -------------Special Authorities-------------
                                                   

          Group    *ALL *AUD SYS *JOB *SAV *SEC *SER *SPL User
Profile  Profiles  OBJ  IT  CFG  CTL  SYS  ADM VICE  CTL Class

X123456  *NONE                              X            *SECADM
Y12344   *NONE      X    X    X   X    X    X    X    X  *SECOFR
3. Look for user profiles that have *ALLOBJ special authority. If there are none, you may find one or more with object management (*OBJMGT) and use (*USE) authority to the QSECOFR user profile. These authorities are required to change the password for QSECOFR.

[{"Type":"MASTER","Line of Business":{"code":"LOB57","label":"Power"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"Platform":[{"code":"PF012","label":"IBM i"}],"Version":"7.1.0"}]

Historical Number

18455814

Document Information

Modified date:
15 September 2020

UID

nas8N1017882