A fix is available
APAR status
Closed as program error.
Error description
ZPRM installation IDs which are groups are not exploded to their connected User IDs if the group is not empty. When using zSecure to provide information to the Guardium Vulnerability Assessment product, DB2 installation IDs defined in the DSNZPARM configuration data set are not replaced by connected user IDs in the RACF_DB2_ACL field by the 'EFFECTIVE' field output modifier in cases where installation IDs are RACF group IDs.
Local fix
N/A
Problem summary
**************************************************************** * USERS AFFECTED: Users of zSecure Audit exploiting Db2 * * resource reports (interactive option RE.D, * * newlist types DB2_xxx). * **************************************************************** * PROBLEM DESCRIPTION: zSecure Audit does not replace DB2 * * installation group IDs defined in the * * DSNZPARM configuration data set by * * connected user IDs in the DB2 * * consolidated access list. * **************************************************************** * RECOMMENDATION: Apply the PTF provided and review the * * documentation update. * **************************************************************** When DB2 installation defined IDs (SYSADM, SYSADM2, SYSOPR1, SYSOPR2, SECADM1, and SECADM2) refer to RACF groups, zSecure Audit does not expand these groups to a list of the connected user IDs in the the DB2 consolidated access list.
Problem conclusion
zSecure Audit has been modified, so that DB2 installation defined IDs SYSADM, SYSADM2, SYSOPR1, SYSOPR2, SECADM1, and SECADM2 are replaced by a list of connected user ID in cases where these installation defined IDs refer to RACF groups in the DB2 consolidated access list. Please note the documentation change as provided by the APAR tracking comment data.
Temporary fix
Comments
APAR Information
APAR number
OA66034
Reported component name
AUDIT-R,A,T ACF
Reported component ID
5655T0200
Reported release
250
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2024-01-19
Closed date
2024-09-13
Last modified date
2024-10-02
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UJ95949 UJ95950
Modules/Macros
CKRDB2A CKRXPL2 GKRDB2A GKRXPL2
Fix information
Fixed component name
ZSEC BASE,ADMIN
Fixed component ID
5655T0100
Applicable component levels
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"250","Line of Business":{"code":"LOB24","label":"Security Software"}}]
Document Information
Modified date:
03 October 2024