IZPSC0022E User 'User' must have read access to profile 'proxyUserSAFProfileName' in the SAF database where UMS is running.

Explanation

The user cannot access the SAF profile of the proxy user in the SAF database. To use a proxy user, a logged-in user must have READ access:
  • To SAF resource (IZP.PROXY.CERT.<keyringowner>.<keyringName>.<keyringLabel>) associated with them.
  • For the client certificate associated with the specific proxy user.
Note: SAF access is validated on the system where UMS and Zowe are running, and not on the system where the certificate is used. This applies even if the certificate is used in a different SAF database (for example, a different sysplex) from the system where UMS is running.

System action

The proxy user authentication will fail.

User response

Check the SAF profile to ensure the user has the required permissions.