IBM Support

Fixes by Version for zSecure Base

Product Documentation


Abstract

A comprehensive list of recommended, generally available (GA) fixes for IBM® Security zSecure® Base releases.

Please note, when zSecure takes part in a Release Beta Program (RBP) alongside z/OS, zSecure PTFs will be published during the RBP which must be applied when installing a zSecure product order from Shopz. These PTFs will generally be supplied with the order, but if the base FMIDs only are applied you will not have fixes for known issues discovered during the RBP.
The RBP PTFs are listed in the relevant tables.

It can take up to 6 months for a published PTF to become part of a Recommended Service Update (RSU). Therefore, if you apply maintenance solely from an RSU, you can still encounter known issues that are resolved by a PTF listed here.

For information, the following document describes the z/OS Consolidated Service Test process used by the RSU packaging team to determine the contents of an RSU, and this process does not include the zSecure suite components:
https://www.ibm.com/support/pages/node/664971

The recommended fixes for zSecure Base included in this document can be relevant to Admin, Audit, Alert, Visual, zSecure Adapters for SIEM and RACF-Offline. The IBM Z Security and Compliance Center component z/OS Compliance Integration Manager may have zSecure base component fixes listed here.

Tables are organized by version in the order they were released.

Content



Recommended fixes table of contents:

 



zSecure Base Release 3.2.0
zSecure Base Release 3.1.0
zSecure Base Release 2.5.0

 



 

 

 

 

 

zSecure Base Release 3.2.0
Documentation updates technote: N/A
IBM APAR
IBM Fix
Description
OA68625UJ98424zSecure version 3.2.0 fix pack (October 2025).
OA68407UJ98323With "Use TSO submit" option, submitting a background job can fail in multi screen mode.
OA68602UJ98294Recreate of a PTKTDATA profile with a SSIGNON segment specifying Replay allowed = YES results in an invalid RALTER command.
OA68320UJ98248AU.V Permit generates commands to delete CICS transaction profiles which have a SECPRFX that is not a user or group.
OA68048UJ98241zSecure Audit and zSecure Adapters for SIEM components report license errors with zSCC only license.
OA68561UJ98239Malformed JSON generated for repeated CARLa fields with UTF-8 encoding.
OA68575UJ98209Incorrect non-compliant findings for compliance evaluations due to incorrect Actual value goal test field.
OA68577UJ98198RA.R incorrectly displays the general resource profile Instdata on the ACL entries.
OA68509UJ98070zSecure version 3.2.0 RBP update (September 2025).
OA68492UJ98069zSecure version 3.2.0 RBP update (September 2025).
OA68399UJ97887zSecure version 3.2.0 RBP update (August 2025).
OA68406UJ97883zSecure version 3.2.0 RBP update (August 2025).
OA68395UJ97882zSecure version 3.2.0 RBP update (August 2025).
OA67942UJ97238zSecure version 3.2.0 RBP update (May 2025).
Additional information
N/A

Go to Top


 

 

 

 

 

zSecure Base Release 3.1.0
IBM APAR
IBM Fix
Description
OA68407UJ98324With "Use TSO submit" option, submitting a background job can fail in multi screen mode.
OA68602UJ98295Recreate of a PTKTDATA profile with a SSIGNON segment specifying Replay allowed = YES results in an invalid RALTER command.
OA68048UJ98242zSecure Audit and zSecure Adapters for SIEM components report license errors with zSCC only license.
OA68561UJ98240Malformed JSON generated for repeated CARLa fields with UTF-8 encoding.
OA68320UJ98205AU.V Permit generates commands to delete CICS transaction profiles which have a SECPRFX that is not a user or group.
OA68525UJ98130Support the CONTAINED and NEVERCONTAIN properties on a RACF USER profile in zSecure Server and zSecure Admin MERGE function.
OA68504UJ98128SEC/INT APAR.
OA68482UJ98127Sample members for defining the zSecure Admin Command Logger logstream do not specify AUTODELETE(YES).
OA68462UJ98126zSecure Alert setup sample jobs C2PZAIN0 and C2PZAIN1 might not perform as expected.
OA68503UJ98107zSecure Admin's fix for compatibility with RACF APAR OA67467.
OA68416UJ98086After restart of C2PACMON using new or modified user ID consolidation may fail if required RACF permits are missing.
OA68449UJ98048CKRP3EUY panel code contains invalid field name COMPLETION_CODET, instead of COMPLETION_CODE.
OA68477UJ98009New function to provide support for IBM CICS Transaction Server V6R3.
OA68473UJ97988Missing support for generation and validation of Identity Tokens (IDT) with RSA-based signatures in zSecure WebUI.
OA68328UJ97988z/OSMF plug-in for zSecure Admin interface level controls do not work as expected.
OA68434UJ97976Remove the serialization capability on SYSZRACF from zSecure to avoid potential enqueue delays.
OA68432UJ97960zSecure PTF UJ97901 for APAR OA68276 might result in various issues related to profiles in the GLOBAL class.
OA68221UJ97925Alert 1506 is configured for SMF Type 90 records, but uses an SMF Type 80 Select statement, causing no alert to be triggered.
OA68319UJ97911zSecure Admin might generate incorrect ALTDSD RACF command when the 'DFP EncTypes' field value is changed in the UI.
OA68276PE - See OA68432CKR0206 issued for GLOBAL profiles while running reports.
OA67653UJ97900Alert verification fails, due to OPTION statment extending beyond column 72.
OA68298UJ97860CIS-OS-6.5.6 incorrectly reports non-compliance for an ID which only has Stack access and is not an FTP user.
OA68190UJ97833Using a NOT parm in a CARLa Select statement can cause no data to be returned.
OA67753UJ97769ABEND0C1 may be seen with zSecure Alert when SDSF is not installed.
OA68258UJ97712SEC/INT APAR.
OA68231UJ97672Support the CONTAINED and NEVERCONTAIN properties on a RACF USER profile.
OA67963UJ97671ABEND002-04 with message C2P0900E when running C2PACMON or C2POLICE under SUB=MSTR.
OA68170UJ97605ABEND0C4-11 at offset 0001CE in routine CKASERI.ADDSDSF.
OA68136UJ97583CKF0354 08 system abend 0C4-11 (invalid storage address - page) during WRTAGGR processing.
OA68103UJ97566zSecure Audit support for: z/OS RACF STIG V9R4, z/OS ACF2 STIG V9R4, and z/OS TSS STIG V9R4.
OA67867UJ97537When using a SELECT/EXCLUDE LIKELIST=name the previous selection of "name" may not be honoured.
OA68106UJ97536ABEND0C4 in CKRLIST.TRUTRE processing SMF type 64 records.
OA67961UJ97536CKR0595 messages issued in error when processing SMF type 42 subtype 27 records.
OA67845UJ97529CKFCOLL may issue messages CKF0028 or CKF0030 related to SDSNLOD2 dataset names.
OA67607UJ97505Encrypted data sets migrated to HSM then recalled are shown to exist in both locations.
OA68102UJ97479Support for SMF records written by IBM CL/Supersession Session manager (SMF record type 225).
OA68008UJ97365DEFINE WHERE and LOOKUP don't work consistently.
OA67882UJ97364CKRCARLA issues an abend processing SMF data.
OA67552UJ97360TLS_SRVR_CERT_SIG_METHOD and TLS_CLNT_CERT_SIG_METHOD help needs updating and default field length needs to be increased.
OA67955UJ97337CKF1024 messages containing garbage data issued when SETROPTS NOWHEN(PROGRAM) is set.
OA67531UJ97336ICSF_DEFAULTWRAP_EXT_ENH and ICSF_DEFAULTWRAP_INT_ENH flag fields incorrectly reported with ICSF level HCR77E0.
OA67694UJ97262STIG controls ZCTD0040, ZCTO0040 & ZIOAR040 fail due to missing information.
OA67779UJ97249C2PAMALC gives error msg IKJ56712I INVALID KEYWORD when using a DA allocation.
OA67799UJ97230CKF0310 08 BPX1RDL errors when the PROC file system exists.
OA67866UJ97164SEC/INT APAR.
OA67778UJ97118Using CARLa select on multiple ljdates results in no data returned.
OA67613UJ97071zSecure Audit incorrectly reports temporary data sets as JESSPOOL resources.
OA67471PE - See OA68434IBM zSecure suite might cause z/OS system lock due to RACF database ENQ contention in sysplex environment.
OA67662UJ97010Incorrect non-compliant finding for CIS-OS-2.1.9 because the key_label field is missing.
OA67217UJ96963Empty datasets incorrectly reported with "empty encr. cells" in CKF0517 with SYMKEYTEST=Y.
OA67560UJ96909ZWMQ0053 reports incorrect non-compliant finding when DISPLAY QMGR DEADQ returns only the alias dead letter queue name.
OA67636UJ96867CIS-OS-7.1.2 control reports incorrect non-compliant finding when no OMVS segment exists for ICSF STC user ID.
OA67343UJ96811R_AC1 Newlist reports programs in non-APF datasets.
OA67497UJ96802RE.K.D does not show encryption key for second and subsequent parts of multi-volume data sets.
OA67479UJ96779Data for char format variable "C2RESM" was too long.
OA67495UJ96754CIS-OS-7.3.5 description mentions incorrect ICSF related profile names.
OA67548UJ96749zSecure Audit support for: z/OS RACF STIG V9R3, z/OS ACF2 STIG V9R3, and z/OS TSS STIG V9R3.
OA67475UJ96748zSecure Access monitor might issue a MSGC2P0571I followed by a MSGC2P0483W.
OA67396UJ96743Alert 1402 triggered for Comms Server API usage of AF_UNIX sockets.
OA67314UJ96720Encryption status and key for migrated VSAM data sets is not shown.
OA67518UJ96716zSecure Audit might display a 'FILE ISPFILE NOT FREED, IS NOT ALLOCATED' followed by a 'File tailoring error' UI message.
OA67536UJ96695Loop in CKRCFS.CKRRDB2 processing DB2 IATTENT data from the CKFREEZE.
OA67273UJ96682CKN125I 08 I/O request without alloc - intermittently seen when restricting access to route RACF commands via CKNSERVE.
OA67481UJ96669RSignWithCA senstype defined with incorrect resource check.
OA67504UJ96643New function to support granular data set encryption.
OA67421UJ96631ZCTMR040 might report incorrect non-compliant results when the BMC IOA Gateway Monitor component is active.
OA67413UJ96604C2POLICE issuing ENQs with a RESERVE on SYSZRACF causing a deadlock.
OA67291UJ96576zSecure version 3.1.0 SSE (January 2025).
OA67279UJ96573zSecure version 3.1.0 SSE (January 2025).
OA67316UJ96573Syntax parsing errors for quoted parms in KLKINNAM.
OA67339UJ96551Alerts 1501 and 1503 produce syntactically incorrect LEEF data due to a missing close brace, " ".
OA67341UJ96551Using overriding output length 0 with LJDATE(EUDATE) changes the year format.
OA67244UJ96418TRUSTED newlist may not report all resources when run in isolation.
OA67205UJ96339Sensitivities AccMonData and zSecFreeze not reported for TRUSTED newlist.
OA67080UJ96330RACF violations with CKFCOLL using CHECKDSN.
OA67173UJ96319zSecure Audit support for: z/OS RACF STIG V9R2, z/OS ACF2 STIG V9R2, and z/OS TSS STIG V9R2.
OA67176UJ96268CKF0002 04 LOCATE return code 8 on LPALST.
OA67129UJ96187zSecure version 3.1.0 SSE (October 2024).
OA66990UJ96186zSecure version 3.1.0 SSE (October 2024).
OA67079UJ96186zSecure Audit does not report a 'Compare result' column while evaluating compliance rules with 'Compare differences' option active.
OA67073UJ96186High CPU in C2POLICE or zSecure Audit using AS_DD, TRUSTED and SENSDSN reports.
OA67028UJ96186CSVLLA senstype should apply to profiles with any number of qualifiers beyond 2.
OA66985UJ96186When loading DB2 data, trailing spaces are added to some fields.
OA66983UJ96186C2PACMON does not collect access event data with racfexitmode direct or csvdynex.
OA66981UJ96186Certificate labels not shown if SE.0 option "Use IO in preference to storage" is selected.
OA66977UJ96186AU.S EXITS may not report on pre-existing RACF post-processing exits when C2PACMON is in use.
OA66959UJ96186Summary Lastuse date and last used time for RA.U display can be from different RACF sources.
OA66434UJ96186CKR2092 08 Buffer overflow: record len 1 but free only 0 byte, record skipped: .
OA66565UJ96007CKXLOG shows password values for SETROPTS RVARYPW commands.
OA66034UJ95949Value -group- is reported instead of connected user IDs from the RACF_DB2_ACL when configuration IDs are RACF Group IDs.
OA66714UJ95942C2P0589E ERROR CREATING PID-NT, RC=0004 PID=C2P_USC.01010013 seen during system startup, after C2PACMON has initialized.
OA66925UJ95935SITE_SEVERITY specification with CONTROL but without RULE does not cause the expected change in AUDITPRIORITY.
OA66876UJ95933Incorrect non-compliant findings for RACF-ES-000080.
OA66870UJ95931ZCIC0030 enforces CICSUSER as CICS default user but DISA does not require this.
OA66962UJ95919ABEND0C4 at CKAOUNIX.CKAUTHOM+8E when comparing SETROPTS options.
OA66919UJ95885Alert 1617 incorrectly triggered multiple times for the same SMF record.
OA66831UJ95883PROGRAMs residing in non-sensitive datasets are incorrectly reported causing non-compliant findings in compliance controls.
OA66914UJ95881After PTF UJ95655 recreating a userID with a password interval other than the default creates invalid alu interval(xx) command.
OA66889UJ95838z/VM V7.4 toleration.
OA66875UJ95835ABEND0C4-04 at offset 00067E in routine CKROUOPT.
OA66874UJ95819SYSTEM newlist field icsf_P11_MKVP_date not reported correctly.
OA66794UJ95765zSecure Audit support for: z/OS RACF STIG V9R1, z/OS ACF2 STIG V9R1, and z/OS TSS STIG V9R1.
OA66841UJ95754Recreate of CFIELD resource optimized for post-processing does not recreate the installation data field.
OA66816UJ95728Incorrect non-compliant findings for RACF-SL-000030 when multiple CKFREEZE files are allocated.
OA66705UJ95723CKR999I 16 Storage shortage for task PROGRAM heap PROGRAM4 in CKRCARLA - increase REGION.
OA66569UJ95655After APAR OA66357, when recreating a user, a syntax error is reported for the command generated.
OA66538UJ95633CSDATA field in user profile not shown through indirect lookup.
OA66630UJ95605ABEND013-C0 trying to allocate C2REMAIL when running C2POLICE with SUB=MSTR.
OA66445UJ95476CKFCOLL abends with S30A-1C when processing MQ data.
OA66469UJ95473New function to provide support for IBM CICS Transaction Server V6R2.
OA66599UJ95416TRUSTED newlist does not correctly enable pre-selection resulting in long run times.
OA66600UJ95370High CPU in CKQRADAR and CKQCEF.
OA66391UJ95351Excessive CPU consumed with NEWLIST TYPE=RACF_ACCESS_ID due to no pre-selection.
OA66411UJ95336CKFREEZE is missing the individual JES2 STC proclib members if the SSI path is being used to obtain the PAD.
OA66212UJ95302RA.5.2 generates RACDCERT command with parameters ICSF and SIZE(4096) resulting in IRRD125I.
OA66471UJ95292Storage growth running CKGRACF ACCESS commands in REXX in BMC AMI OpsAutomation TSO environment.
OA66474UJ95282zSecure Admin does not display the complex name on non-base segment displays for general resources profiles.
OA66448UJ95188Abend 0C4-10 in CKFLMOD.CKFALM.
OA66229UJ95177Trusted report incorrectly adds 40 to priority causing JESNEWS to be reported as non-compliant.
OA66357UJ95172MFA settings for a userid do not get recreated without selecting CKGRACF support.
OA66265UJ95136ABEND0C4-10 in IGVCPOOL in nucleus, along with message C2P0483W.
OA66291UJ95112Alert 1402 triggered incorrectly for pseudotermial (pseudo-TTYs) files.
OA66241UJ95071Running a compare query (show differences) and then submitting the query from the RESULTS panel results in CKR0002 message.
OA65979UJ95069CKR0305 messages seen when processing RMM CDS tape dataset information in a CKFREEZE.
OA66278UJ94977zSecure version 3.1.0 SSE (March 2024).
OA66201UJ94977Description of allowlist members used is not included in print format compliance output.
OA66108UJ94852Incorrect non-compliant findings for ZWMQ0054 when MQ mixed case support uses class MXQUEUE.
OA66140UJ94723zSecure Audit support for: z/OS RACF STIG V8R13, z/OS ACF2 STIG V8R14, and z/OS TSS STIG V8R12.
OA66009UJ94705If an ALLOC TYPE=ASSERT DSNPREF specification causes a PDS to be included, omit it from the input.
OA65920PE - See OA66278ABEND0C9-09 at offset 000E3A in routine CKFCAT.
OA66120UJ94672CKR0103 12 Field "PHRASEINT_PHRASEINT_EFFECTIVE" to be processed not found in any template.
OA65942UJ94642STIG controls report incorrect results with CL/Supersession 3.1.
OA66088UJ94637zSecure Audit might ABEND0C4 while processing sensitive resource data.
OA66102UJ94632Compliance assertion validity end date is not checked correctly.
OA66106UJ94615SMF support for RACF RVARY password protection enhancement (SETROPTS sub-keyword).
OA66055UJ94609CKR0991 16 Unexpected ANY_ pointer 00000050ABF2A0D0. E3D7C6C9 *TPFI* in CKROBJ.
OA66065UJ94571When selecting a customizable alert the customizaton panel is not shown but we return back to the list of alerts.
OA65952UJ94487Incorrect reporting for RACF-VT-000010.
OA65837UJ94462CKG669I 24 Internal error in procedure CKGIRD.
OA65864UJ94399NEWLIST TYPE=SYSTEM fields not populated correctly because RACF DB information is not referenced.
OA65970UJ94377zSecure Audit might generate incorrect 'SMF subsystem-dependent settings' report.
OA65903UJ94370Control ZCIC0042.1 is not shown for standard RACF_CICS_STIG.
OA65931UJ94368zSecure Audit might generate incomplete AS_DD, SENSDSN, and TRUSTED reports.
OA65833UJ94310Compliance controls do not use effective pre-selection for the ACF2_SENSRESOURCE_ACCESS newlist.
OA65618PE - See OA65931Hyper-PAV alias address usage can result in incorrect audit concerns (false positives).
OA65870UJ94256zSecure Audit support for: z/OS STIG ACF2 8.13, z/OS STIG TSS 8.11, and CIS Benchmark for RACF 1.1.0.
OA65817PE - See OA65931zSecure Audit might loop while processing Address Space DD names/Sensitive data set names reports.
OA65839UJ94239SDSFVaryDev sensitivity reported incorrectly for READ access.
OA65835UJ94155zSecure Audit might issue a MSGCKR0788.
OA65789UJ94151Incorrect UNICODE characters in MIME/HTML email.
OA65796UJ94145AU.R.S for single standard controls reports a version of question mark (?).
OA65689UJ94143Show differences report may show USERID(->) when comparing different RACF DBs.
OA65463UJ94139Activating Alert 1124 causes unnecessary processing of SMF records.
OA65769UJ94128PassTicket generation failure SMF record reported as success in SMF newlist.
OA65640UJ94120Incorrect non-compliant findings for RACF-ES-000240.
OA65541UJ94068Incorrect non-compliant findings for RACF-ES-000540 when CONTROL access is in effect.
OA65698UJ94045Lookup on select of a two-pass query with an Unload does not produce expected results.
OA65741UJ94042RE.K.S shows unprintable key labels with non-zero COUNT_DATASET_BACKUP values.
OA65682UJ93995zSecure issues MSGCKR0316 and MSGCKR0000 in cases where only a Top Secret license is enabled.
OA65639UJ93979SMF type 82 records might have an incomplete SAF resource name.
OA65695UJ93968zSecure might issue a MSGCKR0260 while processing system data (CKFREEZE).
OA65641UJ93885SEC/INT APAR.
OA65434UJ93846Group-audit authority is not properly supported in restricted mode.
OA65612UJ93844CKFCOLL incorrectly determines ACF2 is the ESM if a task called ACF2 is running.
OA65469UJ93842When using ID MUST BE PRESENT in Access Monitor reports the generated CARLa code uses inefficient syntax.
OA65538UJ93743zSecure late September 2023 update in preparation for GA.
OA65508UJ93673zSecure version 3.1.0 RBP update (September 2023).
OA65507UJ93672zSecure version 3.1.0 RBP update (September 2023).
OA65506UJ93671zSecure version 3.1.0 RBP update (September 2023).
OA65477UJ93658zSecure version 3.1.0 RBP update (September 2023).
OA65263UJ93332zSecure version 3.1.0 RBP update (August 2023).
OA65266UJ93316zSecure version 3.1.0 RBP update (August 2023).
OA65259UJ93315zSecure version 3.1.0 RBP update (August 2023).
OA64938UJ92881zSecure version 3.1.0 RBP update (May 2023).
OA64937UJ92880zSecure version 3.1.0 RBP update (May 2023).
OA64887UJ92876zSecure version 3.1.0 RBP update (May 2023).
Additional information
N/A

Go to Top


 

 

 

 

 

zSecure Base Release 2.5.0
IBM APAR
IBM Fix
Description
OA68503UJ98108zSecure Admin's fix for compatibility with RACF APAR OA67467.
OA68477UJ98010New function to provide support for IBM CICS Transaction Server V6R3.
OA68221UJ97926Alert 1506 is configured for SMF Type 90 records, but uses an SMF Type 80 Select statement, causing no alert to be triggered.
OA67753UJ97770ABEND0C1 may be seen with zSecure Alert when SDSF is not installed.
OA67314UJ96721Encryption status and key for migrated VSAM data sets is not shown.
OA67504UJ96644New function to support granular data set encryption.
OA67339UJ96552Alerts 1501 and 1503 produce syntactically incorrect LEEF data due to a missing close brace, " ".
OA67080UJ96331RACF violations with CKFCOLL using CHECKDSN.
OA67145UJ96254CKFREEZE is missing the individual JES2 STC proclib members if the SSI path is being used to obtain the PAD.
OA67132UJ96193High CPU in C2POLICE or zSecure Audit using AS_DD, TRUSTED and SENSDSN reports.
OA67020UJ96140C2POLICE cannot delete Extended Monitoring CKFREEZE as it still has an enqueue on it.
OA66034UJ95950Value -group- is reported instead of connected user IDs from the RACF_DB2_ACL when configuration IDs are RACF Group IDs.
OA66876UJ95934Incorrect non-compliant findings for RACF-ES-000080.
OA66870UJ95932ZCIC0030 enforces CICSUSER as CICS default user but DISA does not require this.
OA66962UJ95920ABEND0C4 at CKAOUNIX.CKAUTHOM+8E when comparing SETROPTS options.
OA66919UJ95886Alert 1617 incorrectly triggered multiple times for the same SMF record.
OA66914UJ95882After PTF UJ95655 recreating a userID with a password interval other than the default creates invalid alu interval(xx) command.
OA66889UJ95839z/VM V7.4 toleration.
OA66875UJ95836ABEND0C4-04 at offset 00067E in routine CKROUOPT.
OA66551UJ95793ABEND0C4-10 in IGVCPOOL in NUCLEUS, along with message C2P0483W.
OA66841UJ95755Recreate of CFIELD resource optimized for post-processing does not recreate the installation data field.
OA66569UJ95656After APAR OA66357, when recreating a user, a syntax error is reported for the command generated.
OA66538UJ95634CSDATA field in user profile not shown through indirect lookup.
OA66445UJ95477CKFCOLL abends with S30A-1C when processing MQ data.
OA66469UJ95474New function to provide support for IBM CICS Transaction Server V6R2.
OA66391UJ95352Excessive CPU consumed with NEWLIST TYPE=RACF_ACCESS_ID due to no pre-selection.
OA66212UJ95303RA.5.2 generates RACDCERT command with parameters ICSF and SIZE(4096) resulting in IRRD125I.
OA66531UJ95294Trusted report incorrectly adds 40 to priority causing JESNEWS to be reported as non-compliant.
OA66471UJ95293Storage growth running CKGRACF ACCESS commands in REXX in BMC AMI OpsAutomation TSO environment.
OA66448UJ95189Abend 0C4-10 in CKFLMOD.CKFALM.
OA66357UJ95173MFA settings for a userid do not get recreated without selecting CKGRACF support.
OA66291UJ95113Alert 1402 triggered incorrectly for pseudotermial (pseudo-TTYs) files.
OA66241UJ95072Running a compare query (show differences) and then submitting the query from the RESULTS panel results in CKR0002 message.
OA65979UJ95070CKR0305 messages seen when processing RMM CDS tape dataset information in a CKFREEZE.
OA66322UJ94994zSecure Collect might ABEND0C4 while collecting DASD volume information.
OA65920PE - See OA66322ABEND0C9-09 at offset 000E3A in routine CKFCAT.
OA66120UJ94672CKR0103 12 Field "PHRASEINT_PHRASEINT_EFFECTIVE" to be processed not found in any template at CKRCMDV2 line 6.
OA65942UJ94643STIG controls report incorrect results with CL/Supersession 3.1.
OA66106UJ94616SMF support for RACF RVARY password protection enhancement (SETROPTS sub-keyword).
OA66065UJ94572When selecting a customizable alert the customizaton panel is not shown but we return back to the list of alerts.
OA65952UJ94488Incorrect reporting for RACF-VT-000010.
OA65837UJ94463CKG669I 24 Internal error in procedure CKGIRD.
OA65864UJ94400NEWLIST TYPE=SYSTEM fields not populated correctly because RACF DB information is not referenced.
OA65970UJ94378zSecure Audit might generate incorrect 'SMF subsystem-dependent settings' report.
OA65931UJ94369zSecure Audit might generate incomplete AS_DD, SENSDSN, and TRUSTED reports.
OA65833UJ94311Compliance controls do not use effective pre-selection for the ACF2_SENSRESOURCE_ACCESS newlist.
OA65618UJ94270Hyper-PAV alias address usage can result in incorrect audit concerns (false positives).
OA65817PE - See OA65931zSecure Audit might loop while processing Address Space DD names/Sensitive data set names reports.
OA65839UJ94240SDSFVaryDev sensitivity reported incorrectly for READ access.
OA65835UJ94156zSecure Audit might issue a MSGCKR0788.
OA65796UJ94146AU.R.S for single standard controls reports a version of question mark (?).
OA65689UJ94144Show differences report may show USERID(->) when comparing different RACF DBs.
OA65463UJ94140Activating Alert 1124 causes unnecessary processing of SMF records.
OA65769UJ94129PassTicket generation failure SMF record reported as success in SMF newlist.
OA65640UJ94121Incorrect non-compliant findings for RACF-ES-000240.
OA65779UJ94108SEC/INT APAR.
OA65541UJ94069Incorrect non-compliant findings for RACF-ES-000540 when CONTROL access is in effect.
OA65698UJ94046Lookup on select of a two-pass query with an Unload does not produce expected results.
OA65741UJ94043RE.K.S shows unprintable key labels with non-zero COUNT_DATASET_BACKUP values.
OA65682UJ93996zSecure issues MSGCKR0316 and MSGCKR0000 in cases where only a Top Secret license is enabled.
OA65639UJ93980SMF type 82 records might have an incomplete SAF resource name.
OA65641UJ93886SEC/INT APAR.
OA65434UJ93847Group-audit authority is not properly supported in restricted mode.
OA65612UJ93845CKFCOLL incorrectly determines ACF2 is the ESM if a task called ACF2 is running.
OA65469UJ93843When using ID MUST BE PRESENT in Access Monitor reports the generated CARLa code uses inefficient syntax.
OA65493UJ93749Emergency subsystem incorrectly reported as an NJE node by zSecure Audit.
OA65509UJ93733Abend 0C4-10 at offset 000374 in routine CKFIMS.CKFIMSA.
OA65444UJ93641z/OS STIG version 8.12 support in zSecure Audit.
OA65436UJ93640CKRCARLA incorrectly picking up old data set names from inactive CA1 DSNB records.
OA65342UJ93630zSecure MERGE function does not support PHRASEINT and generates invalid RACF commands.
OA65268UJ93585Records from CKXLOG logstreams might be assigned to incorrect COMPLEX if matching CKFREEZE for the SYSTEM is not available.
OA65186UJ93531Handle non-existent data set names in JES2 PROCLIB statements.
OA65178UJ93528Alerts 1214 and 1409 report on NAME field which is not available in the SMF records which trigger them.
OA65308UJ93491Incorrect non-compliant findings for RACF-ES-000850 when non-base segments exist.
OA65306UJ93464Japanese translation of the audit concern ID 1677.
OA65293UJ93391A CARLa report across many systems might be terminated early due to idle-client detection.
OA65118UJ93312Alert 1121 triggered incorrectly.
OA65141UJ93264CKRCARLA issues CKR1475 when running inside Access Monitor.
OA65179UJ93262Missing end of comment code in member C2RH@INS.
OA65110UJ93261zSecure Access Monitor reporting function might issue an ABEND0C4.
OA65146UJ93260Incorrect non-compliant findings for RACF-ES-000380.
OA65175UJ93235Receiving allocation error IKJ56228I at zSecure dialog startup for CKRCMD file.
OA65148UJ93228Add audit concern for UPDATE access to master catalog.
OA65184UJ93218SE.D.N error message when trying to change Menu Option back to zSecure Default.
OA65171UJ93193S878 or 80A when running zSecure within RACF-Offline session.
OA65137UJ93182Messages from RACF commands that are issued on remote CKNSERVE are not visible in local client.
OA65013UJ92966Running RA.3.G more than once in a single ISPF session results in CKR0391 errors.
OA65021UJ92964z/OS STIG version 8.11 support in zSecure Audit.
OA64881UJ92884PKCS12 format password omitted from generated RACDCERT ADD command.
OA64739UJ92870ACL indirect lookup query not returning results from CSDATA.
OA64563UJ92815CKR1483 12 Syslog message SYSSTAT has more than 1 line.
OA64782UJ92799zSecure Alert issues alert 1402 during standard SSHD recovery processing.
OA64829UJ92790Non-compliant findings for RACF-OS-000210 as DIGTCERT profiles do not have UACC=NONE.
OA64797UJ92769Print format RA.U with output options to show KERB segments fails with CKR0218.
OA64695UJ92647Performance improvement for SMF 1154-97 goal processing.
OA64718UJ92637Specifying "M" to email report from RESULTS panel truncates attachment sent.
OA64684UJ92629zSecure Admin/Audit might display an 'Unsupported type' message while using the IN.F function in interactive mode.
OA64698UJ92614CKR1508 24 CKRESRC.GETRESN empty resource name class JESINPUT.
OA64562UJ92424CKF0028 08 SVC 99 RC=12 DAIRFAIL code 035C 0002.
OA64509UJ92403Abend 0C4 in Access monitor STC in module C2PIORTN when collecting Unix data.
OA64504UJ92403AU.R.S results in CKR0425 12 Field "LIMIT" to be processed not valid for NEWLIST TYPE=COMPLIANCE at CKRCMDV line 4.
OA63932UJ92293Alert Verify fails with CKR0987 when specifying :destination.field for text message destination.
OA64158PE - See OA63932Alert 1411 does not report GROUP names used on the PERMIT command.
OA64304UJ92243Empty daily consolidation file on LPARs with few resources.
OA64401UJ92218zSecure version 2.5.0 SSE (February 2023).
OA64305UJ92215zSecure version 2.5.0 SSE (February 2023).
OA64225UJ92214zSecure version 2.5.0 SSE (February 2023).
OA64178UJ92039ABEND0C4-11 in CKFCOLL.HLLENQISGST+X'F8' during C2POLICE execution.
OA64085UJ92031Recreate of RACFVARS profile results in member lists being reversed.
OA63700UJ09748SEC/INT APAR.
OA64095UJ09724C2PACMON, C2POLICE, CKQEXSMF, and CKXLOG may abend during RESTART processing.
OA64080UJ09721ABEND0C4 in C2POLICE at end of CKRCARLA processing.
OA64069UJ09720TRUSTED newlist results in CKR0703 errors when multiple complexes are allocated.
OA64000UJ09704SHA2 related hash algorithms reported as SHA-224, SHA-256, SHA-384 and SHA-512 which does not match Comms Server IP.
OA63970UJ09702zSecure SMF reporting shows a TLS key exchange method of DHE-EC.
OA64070UJ09701zSecure Access Monitor might report incorrect use counts if the CONSOLIDATE command is used.
OA64053UJ09686High CPU in CKRVCONF processing catalog information from a CKFREEZE.
OA64009UJ09685CKF0002 04 LOCATE return code 8 on PROGxx LNKLST data set.
OA64013UJ09674CKR0529 12 Invalid ACCESS VALUE "CREATE ".
OA64056UJ09629zSecure ACF2 Nextkey expansion shows all rules.
OA63686UJ09584MSGCKR2216 received for multiple audit concerns applicable to the same UNIX file sensitivity type.
OA63882UJ09541CKR1952 24 CKRPUTV: Invalid element length for SRCIP.
OA63894UJ09533Error when attempting to "W"rite to a data set from the RESULTS screen.
OA63540UJ09479Incorrect results when using Access Monitor router exit (C2PRTY00) in combination with existing ICHRTX00.
OA63822UJ09447CKR0989 04 Unexpected word "A4CFG1)," at LPALST00 line 1 following application of APAR OA63769.
OA63868UJ09424CKR1483 error for alert 1306.
OA63844UJ09409Receiving "IRR421I ACEE modification detected" with C2POLICE.
OA63716UJ09363CKR0988 12 Syntax error when selecting all options on the zERT selection panels.
OA63769PE - See OA63822CKF0987 04 Syntax error: field name expected instead of dsname at ".),".
OA63698UJ09270CKFCOLL issues S0C4-11 for module CKFPDSE.TRCEIDR.
OA63751UJ09264ABEND0C4-10 in C2PUSC02.
OA63393UJ09263AM.U report panels show jobname unconditionally.
OA63753UJ09243z/VM V7.3 toleration.
OA63746UJ09238JOBTAG field not populated for CICS SMF type 110 records.
OA63748UJ09226STIG ACP00282 does not take into consideration profiles which are less generic than the MVS.START.STC.mmmmmmmm.ssssssss.
OA63677UJ09162Fix pack for IBM Z Security and Compliance Center 1.1 support.
OA63649UJ09128C2POLICE might show CKRCARLA ENQ issues for CKFREEZE file.
OA63696UJ09115Incorrect non-compliant findings for ruleset ZCIC0040.
OA63637UJ09015Improve error messages for missing SCKACUST/SCKACUSV product libraries.
OA63644UJ09011Refresh of Alert configuration fails with "Not authorized for ULOG".
OA63666UJ09095ABEND0C4 in CKRGEVL.
OA63093UJ08952Using DEVICE_CLASS=DASD still results in tape devices being read.
OA63542UJ08862RA.5.1 selection from "Other fields" panel overwrites previous selection.
OA63471UJ08855When an ALLOC statement has TYPE=RACF but the dataset allocated is a zSecure Unload, an ABEND0C1 occurs.
OA63515UJ08854Abend 0C4-04 in routine CKRLIST.#A@CLC while processing JFCB information in a CKFREEZE.
OA63536UJ08835SEC/INT APAR.
OA63226UJ08796SEC/INT APAR.
OA63454UJ08794Specification of OPTION EMPTYLIST=HIDE prevents NEWLIST EMPTYLIST='XXXX' from being effective.
OA63382UJ08788Recovery/retry in program calls C2PUSCPC and C2PSMFPC fails for some abends.
OA63159UJ08771Alert 1125 trigger conditions incorrect.
OA63135UJ08719CKGRACF CMD COMPLETE DENY does not change the status of the queued ASK command.
OA63225UJ08663SVC scan incorrectly detects SVC 222 in IBM SVCs on ACF2 system.
OA63085UJ08626RE.F.M selection from "Other fields" panel overwrites previous selection.
OA63358UJ08625CKF0305 08 BPX1CHD failed rc=000000A4 reason=EDF66220.
OA63372UJ08616Support for RACF/SAF APARs OA61951 and OA61952 for phrase interval display and management.
OA63366UJ08601zSecure version 2.5.0 SSE (May 2022) - Adapters for SIEM - TSS.
OA63352UJ08589zSecure version 2.5.0 SSE (May 2022) - Audit for TSS.
OA63353UJ08588zSecure version 2.5.0 SSE (May 2022) - Adapters for SIEM - RACF.
OA63338UJ08576zSecure version 2.5.0 SSE (May 2022) - Audit for RACF.
OA63333UJ08572zSecure version 2.5.0 SSE (May 2022).
OA63332UJ08571zSecure version 2.5.0 SSE (May 2022).
OA63110UJ08499ABEND0C4 in C2PRTY00 - the SAF router exit for PROGRAM class.
OA62611UJ08431RA.2 - When trying to delete a PR command the error message is confusing.
OA63114UJ08331CKR0286 messages issued for SENSDSN reporting.
OA63173UJ08291zSecure version 2.5.0 SSE (May 2022).
OA62936UJ08272CKX216E IXGWRITE Failed, RC=00000008-00000806.
OA63092UJ08219New function to provide support for IBM CICS Transaction Server V6R1.
OA62484UJ08196CKF0000 04 Control block hcct omitted because of protection exception.
OA62896UJ08096Flag for expired passphrase not available from RA.U summary display.
OA62982UJ08018CKR0981 and CKR0983 if PROGxx contains an EXIT DELETE statement.
OA62803UJ07997Enhancement to cater for remote syslog devices that break newly established TCP connections.
OA62912UJ07993DSN_MEMBER fields LAST_CHANGE and LAST_CHANGE_USERID empty for PDS members.
OA62914UJ07987CKF0588 08 system abend 0C4-11 (invalid storage address - page) accessing OMVS kernel address space OMVS ASID 0010.
OA62821UJ07987CKF0592 error messages when running CKFCOLL.
OA62862UJ07911ID lookup from ACL field to a target field in a non-BASE segment produces no output when indexed I/O is used to read a RACF DB.
OA62514UJ07910C2POLICE reports error messages CKR0213 and CKF0178.
OA62745UJ07706Message CKR3215 issued if a dsn member allocation exceeds 44 characters.
OA62761UJ07689C2PACMON abend recovery does not remove UNIX exit routines.
OA62663UJ07645Collect started task may be automatically started by C2POLICE when Option CollectTime(0000) is set.
OA62694UJ07612When omitting explicit complex names on ALLOC statements, matching CKFREEZE files are not automatically provided.
OA62593UJ07594CKR0304, CKR0307, CKR0308 and CKR0311 messages seen when CA1 TMC data set migration info in a CKFREEZE is processed via CKNSERVE.
OA62572UJ07587Print format of RA.U/G/R/D with "Shows differences" does not report the differences.
OA62634UJ07580IRR421I ACEE MODIFICATION DETECTED FOR C2POLICE.
OA62592UJ07481CKR1483 error for alert 1401 for RACF rename DACCESS violation.
OA62474PE - See OA62745System symbols not resolved prior to CKRCARLA obtaining ENQ.
OA60881UJ07446TRUSTED newlist shows user ID has access to a data set, even when it has PERMIT AC(NONE).
OA62454UJ07411CKF0991 16 Unexpected UNIT pointer 00000000. 000A0000 * . * in CKFMAIN.CONTEXT - user abend 991.
OA62470UJ07261Panelid C2RP3SI2 does not account for PFKeys and Swapbar.
OA62481PE - See OA62634IRR421I ACEE modification detected for C2POLICE.
OA62292UJ07204zSecure 2.5.0 post-GA update (December 2021).
OA62480UJ07185Modify CKGRACF to ease interfacing with password synchronization tools.
OA62440UJ07181CONVERT to SMFTIME or SMFTIMESTAMP does not work correctly in print mode (SUMMARY).
OA62359UJ07160ABEND0C4-11 in CKR8Z12 occasionally seen in CKNSERVE.
OA61790UJ07152The C2PCBLD procedure does not substitute the C2POLICE variable used in a custom alert skeleton.
OA62395UJ07126CKRZPOST tries to copy members which no longer exist.
OA62411UJ07090zSecure Audit might ABEND0C7 while processing various reports which refer to CICS related data stored in a CKFREEZE data set.
OA62377UJ06994RECORDDESC for SMF type 119(70) does not report AT-TLS.
OA62340UJ06950Certificate related sensitivity types not reported when DIGTCERT class is inactive.
OA62303PE - See OA62411TRUSTED report does not correctly reflect protection with ACF2/CICS.
OA62236UJ06844RACF SMF TYPE=80 events with a missing CLASS do not result in a LEEF record being generated.
OA62249UJ06826Detail missing from RECORDDESC field for ACCESS events.
OA61208UJ06652zSecure version 2.5.0 RBP update (September 2021).
OA62111UJ06651zSecure version 2.5.0 RBP update (September 2021).
OA61867UJ06160zSecure version 2.5.0 RBP update (July 2021).
OA61865UJ06156zSecure version 2.5.0 RBP update (July 2021).
OA61322UJ06156Support for RACF databases in VSAM format.
OA61665UJ05924zSecure version 2.5.0 RBP update (June 2021).
OA61421UJ05576zSecure version 2.5.0 RBP update (May 2021).
OA61401UJ05574zSecure version 2.5.0 RBP update (May 2021).
OA61420UJ05573zSecure version 2.5.0 Release Beta Program (RBP) update (May 2021).
OA61308UJ05374z/OS 2.5 compatibility.
Additional information
N/A

Go to Top

[{"Type":"MASTER","Line of Business":{"code":"LOB70","label":"Z TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"ARM Category":[{"code":"a8m0z000000bm5wAAA","label":"zSecure Admin"}],"ARM Case Number":"","Platform":[{"code":"PF035","label":"z\/OS"}],"Version":"2.5.0;3.1.0"},{"Type":"MASTER","Line of Business":{"code":"LOB70","label":"Z TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SST66D","label":"IBM zSecure Admin"},"ARM Category":[{"code":"a8m0z000000GoZvAAK","label":"zSecure Admin-\u003EInstallation \/ Configuration \/ Upgrade \/ Usage \/ Planning"}],"Platform":[{"code":"PF035","label":"z\/OS"}],"Version":"3.2.0"}]

Document Information

Modified date:
19 November 2025

UID

swg27010596