IBM Support

PK78794: RACF ACCESS AUTHORITY ERROR MESSAGE ICH408I ALONG WITH QCF IQC7008E IS RECEIVED FROM THE QCF SERVER

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • This occurs when the QCF server is started before IMS
    and shows up as a RACF authority issue as:
    ICH408I USER(nnnnnnnn) GROUP(nnnnnnnn) NAME(nnnnnnnnn)
    
      IQC..nnnn    CL(FACILITY)
      INSUFFICIENT ACCESS AUTHORITY
      FROM IQC.** (G)
      ACCESS INTENT(UPDATE ) ACCESS ALLOWED(NONE   )
    IQC7008E ALLOCATE REJECTED FOR USERID=nnnnnn   nnnnnnn
    IQC7008E INSUFFICIENT AUTHORITY TO RESOURCE IQC..nnnn
    IQC7008E RACROUTE AUTH R15=00000008 RC=00000008 RSN=00000000
             nnnnnnn
    
    The issue is due to the QCF server starting first, with
    QCF issuing a query request to get all IMS's that started
    before a certain time, but the IMS has not fully joined the
    plex, therefore it is not showing in the query.
    After IMS joins the plex, SCI sends a message to the server, but
    the message is ignored, because its time is earlier.
    
    Keywords: MSGICH408I IQC7008E
    

Local fix

  • If the QCF server, SCI and IMS are in a startup stream, it
    would be better to reorder them and start SCI, IMS and then
    the server.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of QVF3.1, that run the product    *
    *                 with authorization ( RACF).                  *
    ****************************************************************
    * PROBLEM DESCRIPTION: OS name is missing from facility name   *
    *                      when checking for RACF security. As     *
    *                      result the security check can not be    *
    *                      done correct. This happens only if QCF  *
    *                      server is started first, then IMS is    *
    *                      started. On start up no OS name is      *
    *                      present in event input, and the OS name *
    *                      is not moved into member after the      *
    *                      query.                                  *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When IMS is started first and then QCF server-a query is done
    by server to find all active members in plex and to build
    the control blocks for each member
    (Control block includes the OS name among all other
    info). OS name is present in query output for each member -
    and it is moved to member's control block.
    When IMS is started after the QCF server-an event exit is
    activated and info is passed to build the member's control
    block for the member that becomes active. The passed info
    does not contain the OS name and the control block for
    the member is not complete. QCF server performs a query
    to get all needed info for the member, but does not
    move the OS name from query block to member's block -
    next RACF requests build facility names with empty
    OS name. The OS name should be moved after query.
    

Problem conclusion

  • The event exit action is improved to move the OS name into the
    member's block for the member that becomes active and calls
    the event exit.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PK78794

  • Reported component name

    IMS QUEUE CNTL

  • Reported component ID

    5697E9900

  • Reported release

    310

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2009-01-15

  • Closed date

    2009-01-19

  • Last modified date

    2009-02-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UK43273

Modules/Macros

  •    IQCZCSV0
    

Fix information

  • Fixed component name

    IMS QUEUE CNTL

  • Fixed component ID

    5697E9900

Applicable component levels

  • R310 PSY UK43273

       UP09/01/20 P F901

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Line of Business":{"code":null,"label":null},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCX8A6","label":"IMS Queue Control Facility"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"3.1.0"}]

Document Information

Modified date:
03 October 2020