You normally would save the *USRPRFs using SAVSECDTA or the QSRSAVO API and then restore the profiles using RSTUSRPRF. This would generally be a one time effort.
To keep the profiles in synch across the partitions you can use various APIs and exits which allow you to know when a profile has changed (or a new one created) and then propogate the changes to one or more other system/partitions. The Security related APIs and exits can be found <a href=”http://publib.boulder.ibm.com/infocenter/iseries/v5r4/topic/apis/sec1.htm”>here</a> and the Save Object API <a href=”http://publib.boulder.ibm.com/infocenter/iseries/v5r4/topic/apis/qsrsavo.htm”>here</a>. The book APIs at Work Second Edition (which I do have a financial interest in) also discusses this very scenario in Chapter 12 – Security APIs.
Another possible way to keep the profiles synchronized is with <a href=”http://publib.boulder.ibm.com/infocenter/iseries/v5r4/topic/rzaih/rzaihuseradmin.htm”>Management Central</a>.
Integrated solutions for the System i user community