Troubleshooting
Problem
Authority errors occur accessing IBM i DDM/DRDA server when the user making the connection does not have authority to the SQL package that the connection is using.
Resolving The Problem
An authority error was received when a user tried to connect from an IBM System p system to an IBM i system by using DB2 Information Integrator. The error occurred for any profile other than QSECOFR.
The QRWTSRVR job log showed the DDM connection and no authority errors were displayed.
Running the TRCCNN command on the DDM connection showed:
When a DDM client accesses IBM i, an SQL package is used for the SQL statements. The profiles, other than QSECOFR, did not have authority to the SQL package SYSSH200 in library NULLID. After the user that was making the DDM connection was granted *USE authority to the SQLPKG, the authority error no longer occurred and the SQL statements ran successfully.
Granting the user making the DDM connection *USE authority to the SQLPKG allowed the SQL statements to run.
For more information about modifying SQL package authorities, see https://www.ibm.com/docs/en/i/7.4?topic=package-modifying-authorizations
The QRWTSRVR job log showed the DDM connection and no authority errors were displayed.
Running the TRCCNN command on the DDM connection showed:
Receive - Object ID: - SQLSTT - SQL Statement
Send - Object ID: - SQLCARD - SQL Communications Area Reply Data [with:
------------------------------
SQLCODE: -551
SQLSTATE: 42501
SQLERRPROC: qrwtexec
SQLRDBNME: TRILOGY
SQLERRD: {0,0,0,0,0,0}
SQLWARN: { , , , , , , , , , , }
SQLERRML: 29
SQLERRMSG: NULLID .SYSSH200 .PACKA
SQLCODE 551 maps to an SQL0551 - Not authorized to object &1 in &2 type *&3. When a DDM client accesses IBM i, an SQL package is used for the SQL statements. The profiles, other than QSECOFR, did not have authority to the SQL package SYSSH200 in library NULLID. After the user that was making the DDM connection was granted *USE authority to the SQLPKG, the authority error no longer occurred and the SQL statements ran successfully.
Granting the user making the DDM connection *USE authority to the SQLPKG allowed the SQL statements to run.
For more information about modifying SQL package authorities, see https://www.ibm.com/docs/en/i/7.4?topic=package-modifying-authorizations
Related Information
[{"Product":{"code":"SWG60","label":"IBM i"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"Data Access","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"LOB57","label":"Power"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"Component":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB57","label":"Power"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"Component":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB57","label":"Power"}}]
Historical Number
463334531
Was this topic helpful?
Document Information
Modified date:
21 June 2021
UID
nas8N1014119