IBM Support

PI20582: APPLICATION ATTEMPT TO DO AUTHORIZATION WITH SAF FAILS W/ERROR CODE OF 03008XXX (IF SYNCTOOSTHREAD IS ENABLED)

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When SyncToOSThread is enabled, an application attempt to do
    authorization with SAF may fail with an internal error code of
    03008xxx.  The error code indicates the attempt was rejected by
    the WLP z/OS System Security Access Domain, which controls which
    SAF resources the WLP server is permitted to query.   Even
    though the server's ID is permitted to query the relevant SAF
    resources, the attempt fails when SyncToOSThread is enabled
    because the access domain incorrectly checks the sync'ed ID, not
    the server's ID.
         Internal error codes 03008208 or 03008408 are most likely
    and they will be in message very similar to this:  CWWKS2909E: A
    SAF authentication or authorization attempt was rejected because
    the server is not authorized to access the following SAF
    resource: CLASS SERVAUTH. Internal error code 0x03008408
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server Liberty Profile for z/OS             *
    ****************************************************************
    * PROBLEM DESCRIPTION: APPLICATION ATTEMPTING AUTHORIZATION    *
    *                      WITH SAF FAILS WITH REASON CODE         *
    *                      03008408, IF SYNCTOOSTHREAD IS          *
    *                      ENABLED.                                *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When SyncToOSThread is enabled, an application attempting to do
    authorization with SAF may fail with an internal error code of
    03008xxx.
    The error code indicates the attempt was rejected by
    the WebSphere Application Server Liberty Profile for z/OS
    System Security Access Domain, which controls which
    SAF resources the WLP server is permitted to query.
    Even though the server's ID is permitted to query the relevant
    SAF
    resources, the attempt fails when SyncToOSThread is enabled
    because the access domain incorrectly checks the sync'd ID, not
    the server's ID.
    
    Internal error codes 03008208 or 03008408 are most likely
    and they will be in messages very similar to this:
    CWWKS2909E: A SAF authentication or authorization attempt was
    rejected because the server is not authorized to access the
    following SAF resource: CLASS SERVAUTH. Internal error code
    0x03008408
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PI20582

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-06-23

  • Closed date

    2015-02-19

  • Last modified date

    2015-02-19

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

  • R800 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"800","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 April 2022