IBM Support

OA60687: ALERT 2102 ALLOWS AN EMPTY SELECTION LIST AND ALERTS ON ALL USERS

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Emergency user configuration (alerts 1102 and 2102) allow an
    empty selection list. If selection listis empty, subsequently an
    y user who logs on, an alert is generated.
    

Local fix

  • Make sure there is at least one emergency ID. The default is
    IBMUSER
    
    Setup Alert panel: Configuring emergency users (alerts 1102
    and 2102) panel
    
    Note: zSecure Alert expects at least one emergency user to be
    entered. If no input is provided, IBMUSER is used as default.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of zSecure Alert.                  *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Alert product improvements and  *
    *                      fixes that address following issues:    *
    *                                                              *
    *                       - predefined alert IDs 2102/1102       *
    *                         allow an empty selection list and    *
    *                         alerts on all users. With no IDs     *
    *                         specified on the configuration       *
    *                         panel, the alert skeleton generates  *
    *                         CARLa code with an empty selection   *
    *                         list. This matches all user IDs.     *
    *                                                              *
    *                       - predefined alerts IDs 2116, 2117,    *
    *                         2118 and 2119 repeat the same alert  *
    *                         several times. These alerts issue    *
    *                         the same alert because the SELECT    *
    *                         command lacks a LIKELIST=RECENT, so  *
    *                         SMF record in the HISTORY buffer     *
    *                         also trigger the alert.              *
    *                                                              *
    *                       - predefined alert ID 1204 does not    *
    *                         properly generate the 'simulate      *
    *                         priv_user_groups' statement as       *
    *                         expected from its stage-1 CARLa, so  *
    *                         updates to APF data sets by members  *
    *                         of these groups are (still) alerted. *
    *                                                              *
    *                       - the SE.A.A panel does not recognize  *
    *                         active C2POLICE in JES3 system.      *
    *                         Refresh action return "C2POLICE is   *
    *                         not active". If IATUX30 is used for  *
    *                         authority checking in JES3,          *
    *                         a follow-up message is generated in  *
    *                         the STATUS command output JOB        *
    *                         C2POLICE(JOB44435) EXECUTING+        *
    *                         IAT8969 JOB C2POLICE (JOB44435) IS   *
    *                         OWNED BY (C2PSUSER). JOB             *
    *                         C2POLICE(JOB44435) EXECUTING+        *
    *                         IAT8968 JOB C2POLICE (JOB44435)      *
    *                         C2POLICE ON SYZ TIME(01:37) This     *
    *                         adds an unexpected + in the STATUS   *
    *                         response text.                       *
    *                                                              *
    *                       - new alert set does not verify        *
    *                         immediately after it was copied.     *
    *                                                              *
    *                       - Copy (C) action for alert set on     *
    *                         SE.A.A panel does not copy the       *
    *                         recipient entries for individual     *
    *                         alerts. That means, destinations and *
    *                         configuration of individual alerts   *
    *                         are not intialized, but selected     *
    *                         alert with configuration in model    *
    *                         alert set may require entry of these *
    *                         fields.                              *
    *                                                              *
    *                       - verify may generate incorrect CARLa. *
    *                                                              *
    *                       - 'C' line command in alert selection  *
    *                         list does not copy alert             *
    *                         destinations.                        *
    *                                                              *
    *                       - 'C' line command only copied the     *
    *                         (optional) alert customization.      *
    *                                                              *
    *                       - select (S) action for alert on the   *
    *                         SE.A.A panel copies Action command   *
    *                         status from previous selected alert. *
    *                         When C2PECM in not in an alert       *
    *                         entry, the value from previous alert *
    *                         entry is silently used.              *
    *                                                              *
    *                       - Copy (C) action for alert on the     *
    *                         SE.A.A panel does not copy Action    *
    *                         command status from model alert.     *
    *                                                              *
    *                       - Action command status is taken from  *
    *                         list of alert numbers in alert set   *
    *                         entry, not from alert entry.         *
    *                                                              *
    *                       - 'W' line command on the SE.A.A panel *
    *                         returns "Destinations changed" even  *
    *                         when no change was made, and mark    *
    *                         set as "Req" verification.           *
    *                                                              *
    *                       - no easy way documented to clear      *
    *                         alert level destinations.            *
    *                                                              *
    *                       - The option to clear selection check  *
    *                         boxes for all destinations is not in *
    *                         help panels.                         *
    *                                                              *
    *                       - Use of category level destinations   *
    *                         settings is indistinguishable in the *
    *                         alert selection list.                *
    *                                                              *
    *                       - Category level destinations are      *
    *                         stored in the individual alerts, and *
    *                         not flagged as category level.       *
    *                                                              *
    *                       - Cursor in set, category and alert    *
    *                         selection lists does not stay on the *
    *                         current entry. This makes it         *
    *                         difficult to remember where you last *
    *                         executed a command.                  *
    *                                                              *
    *                       - New alert disappears after 'I' line  *
    *                         command in alert selection list.     *
    *                                                              *
    *                       - After APAR OA60200 fix, the site     *
    *                         alert table entry for the new alert  *
    *                         contains blank in C2PETYPE, so the   *
    *                         entry is not recognized as site      *
    *                         alert.                               *
    *                                                              *
    *                       - 'W  line command, destination panel  *
    *                         accepted a MAILLIST reference on     *
    *                         Bcc: field in destination panel, but *
    *                         generates incorrect CARLa.           *
    *                                                              *
    *                       - Panel verification incorrect.        *
    *                                                              *
    *                       - W line command, destination panel    *
    *                         supports Alert destination Unix      *
    *                         syslog with option Write to data     *
    *                         set, and no TCP or UDP destination,  *
    *                         but issues "Mutually exclusive"      *
    *                                                              *
    *                       - alert batch job C2PCBLD, BUILD       *
    *                         command fails with IRX0034I Error    *
    *                         running C2PESETP, line 2630: Logical *
    *                         value not 0 or 1.                    *
    *                                                              *
    *                       - the alert configuration, C2PCUST     *
    *                         data set, was constructed using      *
    *                         C2PCUTIL, IMPORT command.            *
    *                                                              *
    *                       - the IMPORT command did not set       *
    *                         extension variables in the recipient *
    *                         table (C2PIUEMF).                    *
    *                                                              *
    *                      - C2PCBLD does not issue messages when  *
    *                        generation of C2PCUST members fails,  *
    *                        alert batch job C2PCBLD, BUILD        *
    *                        command creates empty CARLa           *
    *                        member(s).                            *
    *                                                              *
    *                       - syntax failures in skeletons or      *
    *                         missing skeleton members interrupt   *
    *                         the generation of CARLa members, but *
    *                         no message issued to SYSTSPRT.       *
    *                                                              *
    *                       - batch alert test (C2PCTEST) issues   *
    *                         alert messages to configured         *
    *                         destination, for old events in SMF   *
    *                         input data sets.                     *
    *                                                              *
    *                       - alert destinations in the alert      *
    *                         CARLa members are used, and not      *
    *                         disabled.                            *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    The fix for this APAR provides following improvements and fixes:
    
     - prevent empty selection list in alert skeleton for
       predefined alert IDs 1102, 1122, 1701 and 2102.
     - add LIKELIST=RECENT in skeleton for predefined ACF2 alerts
       2116, 2117, 2118 and 2119.
     - if users or groups are coded in SENSAPFU, all values are
       generated in SIMULATE PRIV_SENS_GROUP for predefined alert
       1204.
     - accept EXECUTING+ in TSO STATUS output same as EXECUTING;
     - 'C' line command for alert set on the SE.A.A panel now copies
       all destination and extension entries for alerts in the model
       set.
     - action command status is only set when alert action has been
       configured or copied from model alert.
     - 'W' line command at alert level no longer changes
       destinations when nothing was changed in the destination
       display.
     - 'W' line command at the alert level shows a
       "Clear destinations, use global destinations instead"
       checkbox.  This removes the destination specific
       destinations.
     - 'W' line command at the category level shows provides set and
       clear functions, to remove alert level destinations,
       consistent with global destinations.
     - individual alerts show active category destinations with
       value "c" in the alert selection list, instead of "g".
     - Cursor position in set, category and alert selection lists
       points to the entry most recently used.
     - alert entry type C2PETYPE is set for new alert entry after
       'I' command.
     - use of MAILLIST reference on Bcc entry is denied.
     - empty TCP and UDP address values are allow, as long as
       Syslog or ArcSight messages are written to a data set.
     - set extension variables in C2PCUTIL export and import steps,
       delete empty entries in recipient table during SE.A.A panel
       start-up.
     - issue messages in SYSTSPRT during C2PCBLD batch BUILD for
       build failures, set step RC=8 when build failures occurred.
       Remove disfunctional ISPMLIB from catalogued procedures.
     - C2PCTEST adds OPTION SMPTTOFILE, SNMPTOFILE, SYSLOGTOFILE,
       CMDTOFILE in overriding parameters.
    

Problem conclusion

  • zSecure Alert has been modified product improvements and fixes.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA60687

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    240

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-01-04

  • Closed date

    2021-03-04

  • Last modified date

    2021-04-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ04987

Modules/Macros

  • C2P3ZAH  C2P3ZAR  C2P3ZC1  C2PCBLD  C2PCREF  C2PCTEST C2PCUTIL
    C2PESETP C2PP3ZA1 C2PP3ZA2 C2PP3ZA3 C2PP3ZAA C2PP3ZAD C2PP3ZAE
    C2PP3ZAL C2PS1102 C2PS1116 C2PS1117 C2PS1118 C2PS1119 C2PS1122
    C2PS1204 C2PS1701 C2PT3ZAF CKACFEA  CKACMEM  CKAOUMEM CKASINT
    CKGLIST  CKRACLST CKRACT   CKRACTS  CKRCARL@ CKRDANYP CKRFC822
    CKRFMT   CKRGEVL  CKRINPM  CKRINPO  CKRINPS  CKRMRGC  CKRMRGP
    CKROUACC CKROUPUT CKRPDSE  CKRPRLST CKRPRMSG CKRPRTFL CKRSEL
    CKRSENS  CKRSRCON CKRSTCA  CKRSTELM CKRSTORE CKRSTORF CKRVCONF
    GKRACLST GKRACT   GKRACTS  GKRCARL@ GKRCFEA  GKRCMEM  GKRDANYP
    GKRFC822 GKRFMT   GKRGEVL  GKRINPM  GKRINPO  GKRINPS  GKRMRGC
    GKRMRGP  GKROUACC GKROUMEM GKROUPUT GKRPDSE  GKRPRLST GKRPRMSG
    GKRPRTFL GKRSEL   GKRSENS  GKRSINT  GKRSRCON GKRSTCA  GKRSTELM
    GKRSTORE GKRSTORF GKRVCONF
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R240 PSY UJ04987

       UP21/03/17 P F103

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU008","label":"Security"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"240"}]

Document Information

Modified date:
02 April 2021