<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Message from QZSOSIGN that userid is disabled</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/</link>
	<description></description>
	<lastBuildDate>Wed, 19 Jun 2013 04:33:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: cindyd1106</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98376</link>
		<dc:creator>cindyd1106</dc:creator>
		<pubDate>Fri, 28 Oct 2011 15:07:25 +0000</pubDate>
		<guid isPermaLink="false">#comment-98376</guid>
		<description><![CDATA[GREAT! Thanks for your responses!

Hopefully will have this in place by the next time the userid gets disabled...

Cindy]]></description>
		<content:encoded><![CDATA[<p>GREAT! Thanks for your responses!</p>
<p>Hopefully will have this in place by the next time the userid gets disabled&#8230;</p>
<p>Cindy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98340</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Thu, 27 Oct 2011 21:59:54 +0000</pubDate>
		<guid isPermaLink="false">#comment-98340</guid>
		<description><![CDATA[&lt;i&gt;I think *SECURITY and *AUTFAIL should help-&lt;/i&gt;

The one you want for your specific question is *AUTFAIL. The *SECURITY value is, of course, also highly recommended; but I&#039;m not aware of it giving what you need here.

&lt;i&gt;will the journal be automatically created once auditing is turned on- or will I have to create it myself?&lt;/i&gt;

No. And yes.

If you do it directly, you must (1) create a receiver, (2) create journal QSYS/QAUDJRN with the receiver attached that you previously created, then (3) set the enabling system values.

If you do it indirectly, it will all be done for you. But I&#039;m not going to describe that method due to significant potential side-effects that you really ought to understand before doing it. It really should only be done that way when an initial system setup is also being done.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>I think *SECURITY and *AUTFAIL should help-</i></p>
<p>The one you want for your specific question is *AUTFAIL. The *SECURITY value is, of course, also highly recommended; but I&#8217;m not aware of it giving what you need here.</p>
<p><i>will the journal be automatically created once auditing is turned on- or will I have to create it myself?</i></p>
<p>No. And yes.</p>
<p>If you do it directly, you must (1) create a receiver, (2) create journal QSYS/QAUDJRN with the receiver attached that you previously created, then (3) set the enabling system values.</p>
<p>If you do it indirectly, it will all be done for you. But I&#8217;m not going to describe that method due to significant potential side-effects that you really ought to understand before doing it. It really should only be done that way when an initial system setup is also being done.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cindyd1106</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98322</link>
		<dc:creator>cindyd1106</dc:creator>
		<pubDate>Thu, 27 Oct 2011 18:22:24 +0000</pubDate>
		<guid isPermaLink="false">#comment-98322</guid>
		<description><![CDATA[OK- so I am able to start auditing- but what should I audit for? Not sure what will capture what I am looking for. I tried to decipher the diferent options, but still not really sure what will capture which job is coming in that is disabling the user profile...

I think *SECURITY and *AUTFAIL should help- but not sure if any of the communication ones will be helpful...

It has been quite a while since I have done anything with auditing on the AS400, so now I have one more question- will the journal be automatically created once auditing is turned on- or will I have to create it myself?

Thanks again in advance for your input!]]></description>
		<content:encoded><![CDATA[<p>OK- so I am able to start auditing- but what should I audit for? Not sure what will capture what I am looking for. I tried to decipher the diferent options, but still not really sure what will capture which job is coming in that is disabling the user profile&#8230;</p>
<p>I think *SECURITY and *AUTFAIL should help- but not sure if any of the communication ones will be helpful&#8230;</p>
<p>It has been quite a while since I have done anything with auditing on the AS400, so now I have one more question- will the journal be automatically created once auditing is turned on- or will I have to create it myself?</p>
<p>Thanks again in advance for your input!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cindyd1106</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98251</link>
		<dc:creator>cindyd1106</dc:creator>
		<pubDate>Wed, 26 Oct 2011 12:09:37 +0000</pubDate>
		<guid isPermaLink="false">#comment-98251</guid>
		<description><![CDATA[Going to see if auditing is an option as I do not have access to turn it on- Thank you so much for your responses and will keep you posted... Don&#039;t want to fool around with possibly messing up IP communication, so hopefully I will be able to get auditing started...

Thanks again!!!

Cindy]]></description>
		<content:encoded><![CDATA[<p>Going to see if auditing is an option as I do not have access to turn it on- Thank you so much for your responses and will keep you posted&#8230; Don&#8217;t want to fool around with possibly messing up IP communication, so hopefully I will be able to get auditing started&#8230;</p>
<p>Thanks again!!!</p>
<p>Cindy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98229</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 25 Oct 2011 22:15:27 +0000</pubDate>
		<guid isPermaLink="false">#comment-98229</guid>
		<description><![CDATA[Also, once you know the fully-qualified name of the QZSOSIGN job from looking at the history log or QSYSMSG, you could review its joblog to find the CPIAD06 message that should result from an incorrect password. Just before that message, there should be a CPIAD0B message that identifies a remote IP address.

Tom]]></description>
		<content:encoded><![CDATA[<p>Also, once you know the fully-qualified name of the QZSOSIGN job from looking at the history log or QSYSMSG, you could review its joblog to find the CPIAD06 message that should result from an incorrect password. Just before that message, there should be a CPIAD0B message that identifies a remote IP address.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98224</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 25 Oct 2011 19:55:19 +0000</pubDate>
		<guid isPermaLink="false">#comment-98224</guid>
		<description><![CDATA[&lt;i&gt;Unfortunately it does not look like we have an auditing file created on this system…&lt;/i&gt;

If auditing isn&#039;t set up and enabled, the system has effectively been told not to keep the information.

&lt;i&gt;Is there a way to trace communications into the system because it seems that we have narrowed down the time and possibly the days that it is happening…&lt;/i&gt;

I suppose you could use STRCMNTRC, but you&#039;ll really want someone experienced with communications programming to make good sense of it. A reasonably sized trace, perhaps set as *WRAP, might be started. When CPF1393 shows up, the trace could be ended and analyzed. There are other tracing options, but more people have seen basic comm traces. (You could also run various traces on your network, e.g., Ethereal and/or Wireshark, etc.)

You could also use iSeries Navigator and drill down into Network-&gt; IP Policies-&gt; Packet Rules, select Rules Editor. Create a set of rules that journals IP packets. Make sure that the final default rule allows everything. I think you&#039;d want the inbound CLIENTACCESS_8476_TCP_FC and CLIENTACCESS_9476_TCP_FC services set for  JRN = FULL.

&lt;b&gt;But if the system has never had anyone working successfully with these rules&lt;/b&gt;, I sure can&#039;t recommend it. You can block TCP/IP access real quick with packet rules, and it can take some tricky footwork to dance around them if you&#039;re not prepared.

IMO, the best choice is simply to start auditing. Let the system do what it&#039;s already capable of doing.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>Unfortunately it does not look like we have an auditing file created on this system…</i></p>
<p>If auditing isn&#8217;t set up and enabled, the system has effectively been told not to keep the information.</p>
<p><i>Is there a way to trace communications into the system because it seems that we have narrowed down the time and possibly the days that it is happening…</i></p>
<p>I suppose you could use STRCMNTRC, but you&#8217;ll really want someone experienced with communications programming to make good sense of it. A reasonably sized trace, perhaps set as *WRAP, might be started. When CPF1393 shows up, the trace could be ended and analyzed. There are other tracing options, but more people have seen basic comm traces. (You could also run various traces on your network, e.g., Ethereal and/or Wireshark, etc.)</p>
<p>You could also use iSeries Navigator and drill down into Network-&gt; IP Policies-&gt; Packet Rules, select Rules Editor. Create a set of rules that journals IP packets. Make sure that the final default rule allows everything. I think you&#8217;d want the inbound CLIENTACCESS_8476_TCP_FC and CLIENTACCESS_9476_TCP_FC services set for  JRN = FULL.</p>
<p><b>But if the system has never had anyone working successfully with these rules</b>, I sure can&#8217;t recommend it. You can block TCP/IP access real quick with packet rules, and it can take some tricky footwork to dance around them if you&#8217;re not prepared.</p>
<p>IMO, the best choice is simply to start auditing. Let the system do what it&#8217;s already capable of doing.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cindyd1106</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98212</link>
		<dc:creator>cindyd1106</dc:creator>
		<pubDate>Tue, 25 Oct 2011 15:52:03 +0000</pubDate>
		<guid isPermaLink="false">#comment-98212</guid>
		<description><![CDATA[HI,

Yes I was able to find the CPF1393 message within the history log- but it does not give me any indication as to what job is trying to access the system that is disabling the user profile. That gives me the time the userid is disabled and information about the qzsosign job, but not where the incoming job is coming from. This is coming from a remote job or server or user...

But thank you for your input.

Is there a way to trace communications into the system because it seems that we have narrowed down the time and possibly the days that it is happening...

Thanks!!!]]></description>
		<content:encoded><![CDATA[<p>HI,</p>
<p>Yes I was able to find the CPF1393 message within the history log- but it does not give me any indication as to what job is trying to access the system that is disabling the user profile. That gives me the time the userid is disabled and information about the qzsosign job, but not where the incoming job is coming from. This is coming from a remote job or server or user&#8230;</p>
<p>But thank you for your input.</p>
<p>Is there a way to trace communications into the system because it seems that we have narrowed down the time and possibly the days that it is happening&#8230;</p>
<p>Thanks!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wpoulin</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98211</link>
		<dc:creator>wpoulin</dc:creator>
		<pubDate>Tue, 25 Oct 2011 15:28:04 +0000</pubDate>
		<guid isPermaLink="false">#comment-98211</guid>
		<description><![CDATA[CindyD1106,

You could also look in the system log.  Use DSPLOG PERIOD((*AVAIL *BEGIN) (*AVAIL *END)) MSGID(CPF1393).  This will isolate when profiles are being Disabled.  Then use DSPLOG to see if you can identify the job they were using to attempt to sign on.

Hope this helps,
Bill Poulin]]></description>
		<content:encoded><![CDATA[<p>CindyD1106,</p>
<p>You could also look in the system log.  Use DSPLOG PERIOD((*AVAIL *BEGIN) (*AVAIL *END)) MSGID(CPF1393).  This will isolate when profiles are being Disabled.  Then use DSPLOG to see if you can identify the job they were using to attempt to sign on.</p>
<p>Hope this helps,<br />
Bill Poulin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cindyd1106</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98202</link>
		<dc:creator>cindyd1106</dc:creator>
		<pubDate>Tue, 25 Oct 2011 12:50:58 +0000</pubDate>
		<guid isPermaLink="false">#comment-98202</guid>
		<description><![CDATA[Unfortunately it does not look like we have an auditing file created on this system...

Thanks for your answer- but do you have any other ideas???

Cindy]]></description>
		<content:encoded><![CDATA[<p>Unfortunately it does not look like we have an auditing file created on this system&#8230;</p>
<p>Thanks for your answer- but do you have any other ideas???</p>
<p>Cindy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/message-from-qzsosign-that-userid-is-disabled/#comment-98172</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 25 Oct 2011 00:29:33 +0000</pubDate>
		<guid isPermaLink="false">#comment-98172</guid>
		<description><![CDATA[If you have message queue QSYS/QSYSMSG created on your system, you should be able to locate message ID CPF1393 in it fairly easily. By looking at the message details, you can get the fully-qualified job name. (Any other means of getting the fully-qualified name is just as good.)

With the fully-qualified job name, use DSPJRN over QAUDJRN to list any T/PW entries that came from that fully-qualified job name. The list should be reasonably small when filtered that much. Look at the journal entry header data to find the remote address of the client.

From there, you&#039;ll have to look at whatever the client is doing to try to sign on. One common problem is a cached password.

Tom]]></description>
		<content:encoded><![CDATA[<p>If you have message queue QSYS/QSYSMSG created on your system, you should be able to locate message ID CPF1393 in it fairly easily. By looking at the message details, you can get the fully-qualified job name. (Any other means of getting the fully-qualified name is just as good.)</p>
<p>With the fully-qualified job name, use DSPJRN over QAUDJRN to list any T/PW entries that came from that fully-qualified job name. The list should be reasonably small when filtered that much. Look at the journal entry header data to find the remote address of the client.</p>
<p>From there, you&#8217;ll have to look at whatever the client is doing to try to sign on. One common problem is a cached password.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/8 queries in 0.011 seconds using memcached
Object Caching 395/396 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-06-19 07:27:26 -->