IBM Support

ICH408I for BPX.FILEATTR.APF and FSUMF073 for attribute "a" when applying CICS PTF

Question & Answer


Question

Why am I receiving message FSUMF073 for extended attribute "a" and message ICH408I for BPX.FILEATTR.APF when I apply maintenance to CICS Transaction Server for z/OS (CICS TS)?

The SMP/E apply log shows the following messages:

  Starting script processing...                                        
  Exploding all components of /INSTALL/usr/lpp/cicsts/c510/wlp/        
                            IBM/DFHWLPAX  using the pax command        
  pax: FSUMF073 ./lib/native/zos/s390x/bbgzadrm: user not authorized to
               restore extended attribute "a"                          
  pax: FSUMF073 ./lib/native/zos/s390x/bbgzafsm: user not authorized to
               restore extended attribute "a"                          
  pax: FSUMF073 ./lib/native/zos/s390x/bbgzachk: user not authorized to
               restore extended attribute "a"                          
  pax: FSUMF073 ./lib/native/zos/s390x/bbgzangl: user not authorized to
               restore extended attribute "a"                          
 :
  pax: FSUMF073 ./lib/native/zos/s390x/bboacall: user not authorized to 
               restore extended attribute "a"                           
  pax: FSUMF073 ./lib/native/zos/s390x/bbgzcsl: user not authorized to  
               restore extended attribute "a"                           
  ** pax command failure: pax ended with status 1                       
  Exiting script with status 1                  

This is the ICH408I message from RACF:

 ICH408I USER(username) GROUP(groupname ) NAME(Doe, John)        
   BPX.FILEATTR.APF CL(FACILITY)                                          
   INSUFFICIENT ACCESS AUTHORITY    

I am applying CICS TS V51 PTF UI49726 for APAR PI67639.

Answer

As documented in the "User response" of message FSUMF073 , To be able to set the "a" attribute, you must have at least READ access to the BPX.FILEATTR.APF facility class profile.

After granting RACF read access to the profile, you should be able to apply the PTF successfully without getting ICH408I or FSUMF073 messages.

See Setting up the UNIX-related FACILITY and SURROGAT class profiles in the z/OS UNIX System Services documentation and Checking that you have the appropriate access in the SMP/E documentation for more information.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF035","label":"z\/OS"}],"Component":"Security","Version":"","Line of Business":{"code":"LOB17","label":"Mainframe TPS"}}]

Product Synonym

CICS/TS CICSTS CICS TS CICS Transaction Server

Document Information

Modified date:
11 October 2017

UID

dwa1406390