IBM Support

OA62289: C4R.CONNECT.=UACC.GROUP.USERID NOT EFFECTIVE FOR ADDUSER

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • C4R.CONNECT.=UACC.group.userid not effective for ADDUSER.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Command Verifier exploiting *
    *                 policy profiles that control the             *
    *                 Connect-UACC setting                         *
    *                 (C4R.CONNECT.=UACC.<group>.<userid>).        *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Command Verifier does not       *
    *                      honor policy profiles that control the  *
    *                      Connect-UACC setting for RACF           *
    *                      ADDUSER command.                        *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    When zSecure Command Verifier policy profiles controlling
    Connect-UACC setting ((C4R.CONNECT.=UACC.<group>.<userid>) are
    in effect, the program ignores these profiles for RACF ADDUSER
    commands.
    

Problem conclusion

  • zSecure Command Verifier has been modified so that policy
    profiles controlling Connect-UACC setting are handled in
    accordance to documentation.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA62289

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    240

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-10-20

  • Closed date

    2021-10-28

  • Last modified date

    2021-12-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ06878 UJ06883

Modules/Macros

  • C4RPIER
    

Fix information

  • Fixed component name

    COMMAND VERIFIE

  • Fixed component ID

    5655T07CV

Applicable component levels

  • R240 PSY UJ06883

       UP21/11/02 P F111

  • R250 PSY UJ06878

       UP21/11/02 P F111

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSRM9V","label":"IBM Security zSecure Command Verifier"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"240"}]

Document Information

Modified date:
02 December 2021