Verify that a password matches the password recorded by an external security manager.
VERIFY PASSWORD >>-VERIFY PASSWORD(data-value)--USERID(data-value)--------------> >--+-----------------------+--+---------------------+-----------> '-CHANGETIME(data-area)-' '-DAYSLEFT(data-area)-' >--+----------------------+--+--------------------+-------------> '-ESMREASON(data-area)-' '-ESMRESP(data-area)-' >--+-----------------------+--+-------------------------+-------> '-EXPIRYTIME(data-area)-' '-INVALIDCOUNT(data-area)-' >--+------------------------+---------------------------------->< '-LASTUSETIME(data-area)-'
Conditions: INVREQ, NOTAUTH, USERIDERR
This command is threadsafe.
Use the VERIFY PASSWORD command to check that a password matches the password recorded by an external security manager for a user ID. The command returns the values recorded by the external security manager for the password. This process is called password verification. If your system uses password phrases in addition to or instead of standard passwords, use the VERIFY PHRASE command instead of the VERIFY PASSWORD command.
Attention: To ensure that passwords are not revealed in system or transaction dumps, clear the password or password phrase fields on the EXEC CICS commands that have a password or password phrase option as soon as possible after use.
Unlike the EXEC CICS SIGNON command, the VERIFY PASSWORD command does not depend upon the principal facility, therefore it can be issued in non-terminal environments such as web applications.
If you specify the system initialization parameter SECVFYFREQ=USRDELAY for the CICS region, CICS enforces a full verification request at least once a day for each user ID that is used to log on to the CICS region. The full verification request using the RACROUTE REQUEST=VERIFYX macro makes RACF record the date and time of last access for the user ID, and write user statistics. The behavior of your applications is the same whether or not you specify the SECVFYFREQ system initialization parameter. CICS checks the user ID at user login and replaces the password verification request with a full verification request when necessary.
Because the full verification request has a higher processor cost and response time than password verification, you might notice a slight performance impact when you specify the SECVFYFREQ system initialization parameter. The extent of the performance impact depends on your setting for the USRDELAY system initialization parameter for the CICS region. When you specify SECVFYFREQ, CICS makes a full verification request for a user ID when the user logs on after the USRDELAY interval has expired. CICS also applies a maximum limit of one day between full verification requests at user login. If your USRDELAY parameter is set to less than 1440 minutes (1 day), a full verification request takes place at user login more frequently than once a day.
CICS also issues a full verification if an incorrect password is entered, and in the next successful request. In other cases, the VERIFY PASSWORD command uses a fastpath method to verify the password. For details of the SAF interfaces used, see CICS security control points.
When the external security manager is RACF, the time is shown as midnight.
If the external security manager is RACF, this field is the RACF reason code.
The external security manager does not always return response and reason codes to CICS. Make sure that you check the EIBRESP and EIBRESP2 values returned by this command in addition to checking the ESMRESP and ESMREASON values.
If the external security manager is RACF, this field is the RACF return code.
The external security manager does not always return response and reason codes to CICS. Make sure that you check the EIBRESP and EIBRESP2 values returned by this command in addition to checking the ESMRESP and ESMREASON values.
When the external security manager is RACF, the time is shown as midnight.
If the ESM does not allow mixed case passwords, the password is converted to uppercase.
The user ID supplied is converted to uppercase.
Default action: terminate the task abnormally.
However, if ESM RESP = 24, the revoke count is not incremented.
Default action: terminate the task abnormally.
Default action: terminate the task abnormally.