APAR status
Closed as program error.
Error description
When the safCredentials configuration specifies suppressAuthFailureMessages, and the value is set to false, Liberty will allow SAF to print certain messages (such as ICH408I) when an authorization failure occurs. In the case where a user does not have access to the profile prefix in the APPL class, an ICH408I message is not printed. There will be a CWWKS2907E message in the message log for the Liberty server, indicating the user who lacks access. However this message does not give the SAF administrator the information that they need to assign the correct access to the user.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server Liberty for z/OS * **************************************************************** * PROBLEM DESCRIPTION: Message ICH408I is not printed when a * * user does not have access to the APPLID * * in the APPL class * **************************************************************** * RECOMMENDATION: * **************************************************************** A user who wishes to use the WLP z/OS System Security Access Domain (WZSSAD) in Liberty requires read access to the APPLID in the SAF APPL class. When the suppressAuthFailureMessages is set on the safCredentials configuration in server.xml, Liberty should force SAF to print an ICH408I message when an authorization failure occurs trying to access the WZSSAD. This requires a second RACROUTE FASTAUTH call with message suppression turned off, to force the ICH408I message. The second RACROUTE call was being made with an incorrect ACEE. The second RACROUTE call is not used in the authorization decision; it is only used to print the ICH408I message.
Problem conclusion
The second call to RACROUTE FASTAUTH is changed to use the correct ACEE when forcing message ICH408I for a user who does not have access to the APPLID in the APPL class. The fix for this APAR is currently targeted for inclusion in fix pack 19.0.0.2. Please refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
Temporary fix
Comments
APAR Information
APAR number
PH08497
Reported component name
LIBERTY PROF -
Reported component ID
5655W6514
Reported release
CD0
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2019-02-12
Closed date
2019-02-13
Last modified date
2019-02-13
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
LIBERTY PROF -
Fixed component ID
5655W6514
Applicable component levels
RCD0 PSY
UP
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Platform":[{"code":"PF054","label":"z Systems"}],"Version":"CD0","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
17 June 2020