z/OS Security Server RACF Messages and Codes
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


IRRH503E

z/OS Security Server RACF Messages and Codes
SA23-2291-00

IRRH503E
RACF cannot assign unique UNIX IDs when users or groups that do not have OMVS segments use certain z/OS UNIX services. One or more requirements are not satisfied.

Explanation

The RACF UNIX identity check has determined that you want RACF® to assign unique UNIX IDs when users or groups without OMVS segments use certain z/OS® UNIX services. However, RACF is not able to assign unique UNIX identities for z/OS UNIX services because one or more of the following requirements are not satisfied:
  1. The RACF database is enabled for application identity mapping (AIM) stage 3.
  2. The UNIXPRIV class profile SHARED.IDS is defined and the UNIXPRIV class is active and RACLISTed.
  3. The FACILITY class profile BPX.NEXT.USER is defined and its APPLDATA field has valid ID values or ranges.
  4. The FACILITY class profile BPX.UNIQUE.USER is defined.

See z/OS Security Server RACF Security Administrator's Guide for more information about enabling RACF for automatic assignment of unique UNIX identities.

System action

The check continues processing. There is no effect on the system.

Operator response

Report this problem to the system security administrator.

System programmer response

None.

Problem determination

The check produces a report listing the requirements. An "E" in the "S" (Status) column indicates that a requirement is not satisfied. For example, if the RACF database has not been enabled for AIM stage 3, this requirement is flagged as an exception. If the "S" field is blank, the requirement is satisfied. One or more requirements are not satisfied and have been flagged as an exception in the Status column.

Source

Module

IRRHCR10

Routing code

N/A

Descriptor code

N/A

Automation

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014