On Thu, 23 Jun 2011 11:01:56 -0400, Andy Coburn <[email protected]> wrote:
> > >I question Walt's statement above in one case and one case only. The quote > >below is from the z/OS V1R11 manual Using Data Sets SC26-74410-09: > > > ><quote> > >...snipped (by Walt)... > > > >Note: VSAM OPEN routines bypass RACF security checking if the program > >issuing OPEN is in supervisor state or protection key 0." > > > ></quote> > > > >I call your attention to the last paragraph. I have been hoping that IBM > >will find a way to eliminate this restriction so I won't have to do my own > >RACROUTE REQUEST=AUTH for every VSAM data set I open when I'm in > supervisor > >state or key zero. > > > >I would imagine that not very many COBOL programs run in supervisor state > or > >key zero, but Walt Farrell put on his security hat (his words) so I > thought > >it might be proper to continue his line of thought. > <http://bama.ua.edu/archives/ibm-main.html> You can be fairly certain that *no* COBOL programs run in sup state and/or key zero because LE does not officially support it and not at all without performing unnatural acts. That's not to say you can't conspire to get that to happen, but it would be most unwise to try. -- This email might be from the artist formerly known as CC (or not) You be the judge. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html

