z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Allowing mixed-case passwords (PASSWORD option)

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

If you have the SPECIAL attribute, you can allow mixed-case passwords for all users on all applications on this system and on all systems that share the RACF® database. Use the SETROPTS PASSWORD(MIXEDCASE) option to allow mixed-case passwords at your installation.
SETROPTS PASSWORD(MIXEDCASE) 

Restriction: The ISPF panels do not support the SETROPTS option to activate and deactivate mixed-case password support. For this, you must use the SETROPTS command with the PASSWORD option.

By default, NOMIXEDCASE is in effect and mixed-case passwords are not supported. If you want to allow mixed-case passwords, be sure that mixed-case content is permitted by your password syntax rules. (See Establishing password syntax rules (PASSWORD option).) When SETROPTS PASSWORD(MIXEDCASE) is in effect, the RACF commands ALTUSER, ADDUSER, PASSWORD, and RACLINK no longer translate passwords to upper case, nor do applications that provide mixed-case password support, such as TSO/E and z/OS UNIX.

User considerations: When you activate the MIXEDCASE option, users should be aware of the following considerations.
  • Mixed-case passwords are more secure and harder to guess than uppercase passwords. Users are encouraged to select mixed-case passwords.
  • Users with existing, uppercase passwords need not supply their passwords in upper case. However, once the MIXEDCASE option is activated, any password that is set or changed to a value containing a lowercase character must thereafter be supplied exactly as it was created. In other words, the user must then supply every character of the password using exactly the same case used when the password was created.
  • Users are prevented from entering new passwords that differ from their current passwords by only the case in which they are entered. For example, if a user's current password is IM4JUVE, the user cannot change it to a new password of Im4Juve.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014