Previous Topic: Random Password GenerationNext Topic: Forcing Password Validation in DORMANT and WARN Modes


Preventing Users From Changing Passwords

Although, by default, CA Top Secret allows users to change their passwords, this capability may be revoked system-wide, or revoked for certain users or user groups. To prevent all users in the system from changing their passwords, administrators should set the NU suboption of the NEWPW control option as follows:

NEWPW(NU)

To prevent specific users from changing their passwords, administrators should use the NOPWCHG keyword with either the CREATE or ADDTO functions. This keyword can be attached to either User ACIDs or profiles. For example, the following would prevent USER01 from changing his password:

TSS ADDTO(USER01) NOPWCHG