I have 2 profiles in the APPL class - lets call the APPL1 and APPL2 - with a lot of groups and users on the ACL.
Is there an easy way in zSecure to produce a list over how the ACLs differ between the to profiles - meaning what users do only have access to resource1 APPL1 respectively APPL2?
Tom.Zeehandelaar 2700018KM7144 Posts
Re: Compare 2 resource profiles2013-02-28T11:23:55ZThis is the accepted answer. This is the accepted answer.Hi Lars,
there is a simple CARLa program that you could use to report the different IDs that are permitted on the ACLs of the pertinent APPL profiles. However, this program does not take into account the access level that is permitted. So if a user or group ID has NONE on profile APPL1 and READ on APLL2, that difference does not show.
This program reports only the user or group IDs that are permitted (with any access level) on only one of the two involved APPL profiles.
newlist type=racf empty= 'Permitted IDS on involved profiles are equal', t= 'IDs that are permitted on only on one of the APPL profiles' select class=appl segment=base key=(omvsappl,ussappl) sortlist key( 'APPL profile name') summary userid count(<2,nd)
This is what the result might look like. Be aware that I have artificially created this situation on my system by copying profile OMVSAPPL to USSAPPL and then remove one permit and adding another.
P R O F I L E L I S T I N G 28 Feb 2013 06:21 IDs that are permitted on only on one of the APPL profiles User/grp APPL profile name CRMBOP1 OMVSAPPL CRMBTZ3 USSAPPL
This report shows that ID CRMBOP1 is permitted only to APPL profile OMVSAPPL and ID CRMBTZ3 is permitted only to APPL profile USSAPPL.
Would this program suffice for your purpose?
Best regards Tom Zeehandelaar