IBM Support

PH43801: MFA 2.2 MESSAGE AZF2409S WITH SECURITY MANAGER TOPSECRET

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • MFA 2.2 fails to initialize any MFA authentication factors
    when using security manager TopSecret. It is possible that
    the same failure might occur with security manager ACF2.
    .
    Message "AZF2408I Authenticator not defined
    (MFADEF profile not defined)" is issued for every
    MFA factor, followed by message "AZF2409S No authenticators
    were initialized". The z/OS JOBLOG contains message
    "TSS9999E CA-TSS SECURITY SVC ABEND S0C4 IN TSSKERNL+1188"
    .
    FIXCAT
    MFA/K
    .
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All MFA 2.2 w/security manager TopSecret     *
    ****************************************************************
    * PROBLEM DESCRIPTION: RACROUTE REQUEST=EXTRACT parameter list *
    *                      is built incorrectly.                   *
    ****************************************************************
    * RECOMMENDATION: Install fixing PTF.                          *
    ****************************************************************
    MFA multiple factor instance support performs a RACROUTE
    REQUEST=EXTRACT request with factor name prefixes to obtain a
    list of defined factor instances.  The parameter list for the
    request has the extension offset incorrectly set to 0, which
    causes security manager TopSecret to fail with an ABEND0C4
    processing the request and not return any factor profiles back
    to MFA, so MFA initialization fails.
    
    The incorrect parameter list does not affect security manager
    RACF.
    

Problem conclusion

  • The RACROUTE REQUEST=EXTRACT parameter list initialization has
    been corrected to correctly set the extension offset for the
    request.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH43801

  • Reported component name

    MULTI-FACTOR AU

  • Reported component ID

    565516201

  • Reported release

    220

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-02-01

  • Closed date

    2022-02-02

  • Last modified date

    2022-03-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • AZFBCCTC AZFBCERT AZFBINGE AZFBISAM AZFBLDAP AZFBPTKT AZFBRADP
    AZFBSFNP AZFBSID3 AZFBSIDP AZFBSIDR AZFBTOTP AZFBYUBI AZFCERT1
    AZFCKCTC AZFISAM1 AZFISP64 AZFISPF  AZFLDAP1 AZFPASS1 AZFPTKT1
    AZFRADP1 AZFSFNP1 AZFSIDP1 AZFSIDP3 AZFSIDR1 AZFSTCMN AZFSTCWS
    AZFTOTP1 AZFYUBI1
    

Fix information

  • Fixed component name

    MULTI-FACTOR AU

  • Fixed component ID

    565516201

Applicable component levels

  • R220 PSY UI79156

       UP22/02/08 P F202

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNR6Z","label":"IBM Multi-Factor Authentication for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"220"}]

Document Information

Modified date:
02 March 2022