Also, check the SETROPTS for the PROTECTALL option. If you had a PAGE.* profile, which only covered the 2nd level, the PAGE.A.another_level is NOT protected, and RACF (actually DFSMS) would fail any access to the dataset. When you created PAGE.**, you then covered any number of levels after PAGE., and RACF/DFSMS would then allow access.
And, as previously stated (I think), when you rename a RACF protected dataset, the dataset name that it is renamed to must also be protected. (Level of protection doesn't really matter ... just covered by a profile.) ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html

