(iSeries)
User profiles and authorities
WebSphere Application Server uses two OS/400 user profiles by default, QEJB and QEJBSVR.
The QEJB user profile is shipped as part of the operating system. This user profile is used only when accessing validation list objects used for storing the encoded passwords used with WAS. For more information on using validation list objects to store encoded passwords, see Restore or replace damaged validation list objects
The QEJBSVR user profile is created on your iSeries server when we install WAS. This profile is the default profile under which all application servers run. Directories and files used by WAS are normally owned by user profile QEJBSVR. The WAS runtime, administration tools, and Qshell scripts sets the ownership and authorities correctly on any objects created. If we create objects manually outside of the WAS tools, or if we modify the authorities on objects used by WAS, ensure QEJBSVR has the correct authorities to these objects.
We can also use the grtwasaut script and the rvkwasaut script to modify authorities on integrated file system objects. When we create new directories for WAS, the QEJBSVR user profile must have read and execute authorities (*RX) to those directories.
If we have specified another user profile to run the application servers, IBM recommends specified QEJBSVR for its group profile. See Running application servers under specific user profiles for more information.