IBM Support

OA55133: INCORRECT ORDER OF GENERATED RACF CERTIFICATE NAME FILTER COMMANDS WHEN OVERTYPING DISPLAYED VALUES

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When changing the UserID in an already existing digital
    certificate name filter by over typing it, that zSecure
    generates the commands in the wrong order.
    
    Create a Certificate name filter using the commands
    racdcert ID(CKRTASK) map
    sdnfilter('CN=CKNSAMP1.OU=ZSECURE.O=IBM.C=US') withlabel('CKN
    MAP') trust
    
    Go into RA.5.8 and overtype the Filter user ID
    
    It generates the new filter command first and the delmap command
    second.
    In this order you are left with no certificate name filters at
    all.
    
    If these are executed, it results in an error running the first
    command as the filter already exists however the delmap command
    still executes resulting in no CNF
    

Local fix

  • Manually swap the order of the commands before execution
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Admin exploiting the RA.5.8 *
    *                 (Digital certificate Name filtering) report  *
    *                 in interactive mode.                         *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Admin generated an incorrectly  *
    *                      ordered RACF command sequence after     *
    *                      an overtype of the 'Filter userid'      *
    *                      field.                                  *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    When the 'Filter userid' field is modified on the detail display
    of the RA.5.8 (Digital certificate Name filtering) report,
    zSecure Admin generated an incorrectly ordered RACF command
    sequence that fails to execute.
    

Problem conclusion

  • zSecure Admin has been modified so that a correct RACF command
    sequence is generated after an overtype of the 'Filter userid'
    field on the detail view of the RA.5.8 (Digital certificate Name
    filtering) report.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA55133

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    230

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-03-20

  • Closed date

    2018-04-13

  • Last modified date

    2018-05-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UA95866

Modules/Macros

  • CKRACTM  GKRACTM
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R230 PSY UA95866

       UP18/04/16 P F804

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"}, "Product":{"code":"SSCE68R","label":"zSecure Admin"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"230","Edition":""}]

Document Information

Modified date:
01 May 2018