Hi all ,

In my previous shop we add TSS instead of RACF . I remember we had a way  to
get a user password but I’m not really familiar what was the background
process.

Is somebody familiar with a method to get a user password when using RACF ?

I assume RACF DB is holding the DB in hash base on a one way function , but
I'll also expect that TSS will do the same .

if it truly so , I’ll be interesting on HOW could my previous shop bypass
the basic security (maybe using Exit to insert the password to protected
dataset before the HASH) I’ll expect from a security product to allow only
reset of the password and not reviewing of the user password .


-- 
best regards,
matan cohen
MF System Administrator.

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to