We do not want the give the user access to issue MVS commands -
That is not the way this worked.
The clist does specific functions which the user cannot do directly with MVS 
commands.

Netview 5.4 is doing security checking against the invoking userid which it did 
not do before.
We need a way to stop it from doing so.


-----Original Message-----
From: IBM Mainframe Discussion List [mailto:[email protected]] On Behalf Of 
Shmuel Metz (Seymour J.)
Sent: Friday, August 05, 2011 11:51 AM
To: [email protected]
Subject: Re: Netview security problem

In
<A826B9FD78356242A9D9595912F9B2323A4690FA88@DOITTMAIL03.doitt.nycnet>,
on 08/05/2011
   at 11:03 AM, "Barkow, Eileen" <[email protected]> said:

>Would anyone know what is causing the error below?

Yes; the cause listed in the RACF message manual.

>The RACF group says that nothing was changed on this lpar and the
>Netview programmer is not sure about any changes to security.

Ask the RACF group to check DPCINTAA's access to MVS.ROUTE.CMD.DOFD
CL(OPERCMDS) on both systems.

>The user is not authorized to issue any MVS commands directly but
>has always been allowed to invoke clists

The clist shouldn't be able to do anything that the user isn't allowed
to do.
 
-- 
     Shmuel (Seymour J.) Metz, SysProg and JOAT
     ISO position; see <http://patriot.net/~shmuel/resume/brief.html> 
We don't care. We don't have to care, we're Congress.
(S877: The Shut up and Eat Your spam act of 2003)

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to