KM5_BPX_SUPERUSER
This parameter provides an alternative method for managing privilege checks when the TEMS initializes and needs superuser access (UID=0) to monitor z/OS Unix System Services activities.
Setting the parameter to Y allows OMEGAMON to skip SAF/RACF privilege checks before setting UID=0 to avoid ICH408I audit messages.
LPR1 26085 11:18:37.48 STC99999 60500000 ICH408I USER(OMEGDS ) GROUP(SYSSTC) NAME(OMEGAMON (T) 571
562 60500000 CL(PROCESS )
562 60500000 INSUFFICIENT AUTHORITY TO AUTHCHECK
562 60500000 EFFECTIVE UID(0000520671) EFFECTIVE GID(0000000000)
To ensure the z/OS Agent can monitor z/OS UNIX System Services activities without defining an OMVS segment with uid(0) (or UID=0?), instead permit the TEMS userid READ level access to BPX.SUPERUSER profile in the FACILITY class.
If you don't want this alternative, set KM5_BPX_SUPERUSER to N or leave it out, and the TEMS continues to use the usual SAF/RACF privilege checks.
Do not edit KDSENV directly; maintenance or updates override any changes you make to KDSENV.
- Required or optional
- Optional
- Location where the parameter value is stored
-
The KDSENV member of the &hilev.&rte.RKANPARU
- Default value
- The default is N
- Permissible values
-
Y or N