z/OS Security Server RACF Messages and Codes
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


IRRH504I

z/OS Security Server RACF Messages and Codes
SA23-2291-00

IRRH504I
RACF is not enabled to assign UNIX IDs when users or groups that do not have OMVS segments use certain z/OS UNIX services. If you choose not to define UNIX IDs for each user of UNIX functions, you can enable RACF to automatically generate unique UNIX UIDs and GIDs for you.

Explanation

The RACF UNIX identity check has determined that RACF® is not enabled to assign UNIX IDs when users or groups that do not have OMVS segments use certain z/OS® UNIX services. Users and groups that need to access z/OS UNIX functions and resources should be assigned unique UNIX UIDs and unique GIDs in advance of their need to access these services.

However, if you have many users without OMVS segments that need access to z/OS UNIX services, such as FTP, you might choose not to assign UNIX identities in advance. In these cases, you can enable RACF to automatically assign unique UIDs and GIDs at the time they are needed-when users without OMVS segments access certain z/OS UNIX services.

RACF automatically assigns unique identities for z/OS UNIX services when all of the following requirements are satisfied:
  1. The RACF database is enabled for application identity mapping (AIM) stage 3.
  2. The UNIXPRIV class profile SHARED.IDS is defined and the UNIXPRIV class is active and RACLISTed.
  3. The FACILITY class profile BPX.NEXT.USER is defined and its APPLDATA field has valid ID values or ranges.
  4. The FACILITY class profile BPX.UNIQUE.USER is defined.

However, the FACILITY class profile BPX.UNIQUE.USER is not defined, so RACF is not enabled to automatically assign unique UNIX identities for z/OS UNIX services. If you would like to use this support, see z/OS Security Server RACF Security Administrator's Guide for more information.

System action

The check continues processing. There is no effect on the system.

Operator response

None.

System programmer response

None.

Problem determination

Source

Module

IRRHCR10

Routing code

N/A

Descriptor code

N/A

Automation

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014