IBM Support

PH22450: CICS INITIALIZATION FAILS WITH MESSAGE DFHSI1551 AFTER SPECIFYING KERBEROSUSER IN THE SIT

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • A CICS region startup fails with the following messages when
    setting a UserID for the KERBEROSUSER SIT option:
    
    
    DFHSI1551 - YYYYYYYY - The CICS region userid XXXXXXXX is not
    authorized to use the PLTPIUSR parameter userid
    ZZZZZZZZXXXXXXXX. Initialization cannot continue, so CICS is
    terminated.
    
    
    DFHXS1111 - YYYYYYYY CSXM Security violation by user XXXXXXXX
    for resource WWWWWWWW.DFHINSTL in class SURROGAT.
    SAF codes are (X'00000004',X'00000000'). ESM codes are
    (X'00000004',X'00000000'). RACF request made was FASTAUTH.
    
    
    Definitions are as following:
    PLTPIUSR=XXXXXXXX
    KERBEROSUSER=ZZZZZZZZ
    
    
    The problem only occurs when PLTPIUSR is 8 bytes long and
    KERBEROSUSER is specified.
    

Local fix

  • Use UserIDs with a length smaller than 8
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS Users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: Messages DFHXS1111 and DFHSI1551 being  *
    *                      issued when PLTPIUSR and KERBEROSUSER   *
    *                      are defined in the SIT.                 *
    ****************************************************************
    If the PLTPIUSR specifies an 8 character userid and KERBEROSUSER
    is also defined in the SIT then messages DFHXS1111 and DFHSI1551
    will be issued because the CICS startup fails to correctly
    identify the PLTPIUSR when reading it from SIT storage.
    

Problem conclusion

  • DFHSII1 has been changed to correctly obtain the PLTPIUSR from
    SIT storage.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH22450

  • Reported component name

    CICS TS Z/OS V5

  • Reported component ID

    5655Y0400

  • Reported release

    200

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-02-21

  • Closed date

    2020-03-31

  • Last modified date

    2020-05-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UI68714

Modules/Macros

  • DFHSII1
    

Fix information

  • Fixed component name

    CICS TS Z/OS V5

  • Fixed component ID

    5655Y0400

Applicable component levels

  • R200 PSY UI68714

       UP20/04/02 P F004

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
04 May 2020