Solving permissions issues with Connect:Direct nodes

Use the information in this topic if your transfers between IBM® MQ Managed File Transfer and Connect:Direct® fail with an error about insufficient permissions.

For transfers involving the Connect:Direct bridge, the user ID that connects to the Connect:Direct node is determined by which WebSphere® MQ Message Descriptor (MQMD) user ID is associated with the transfer request. You can map specific MQMD user IDs to specific Connect:Direct user IDs. For more information, see Mapping credentials for Connect:Direct.

You might see transfers failing with one of the following errors:
  • 
    BFGCD0001E: This task was rejected by the Connect:Direct API with the 
    following error message: Connect:Direct Node detected error. 
    LCCA000I The user has no functional authority to issue the selp command
    
  • 
    BFGCD0026I: Connect:Direct messages: The submit of the process 
    succeeded. Process number 1092 (name F35079AE, SNODE MYNODE) 
    executing. User fteuser does not have permission to override SNODEID.
    User fteuser does not have permission to override SNODEID. User 
    fteuser does not have permission to override SNODEID.
    

If you see either of these errors, determine which Connect:Direct user ID is associated with the MQMD user ID that was used for the transfer request. This Connect:Direct user ID must have authority to perform the Connect:Direct operations required by the Connect:Direct bridge. For the list of functional authorities needed, and guidance on how to grant these authorities, see Mapping credentials for Connect:Direct by using the ConnectDirectCredentials.xml file.