The AUTHCHK default change had nothing to do with the VTAM command enhancement, 
except that such commands with or without the MVS prefix are subject to 
security checking.

-----Original Message-----
From: IBM Mainframe Discussion List [mailto:[email protected]] On Behalf Of 
Chris Mason
Sent: Friday, August 05, 2011 3:49 PM
To: [email protected]
Subject: Re: Netview security problem

Eileen

So does this NETVIEW AUTHCHCK SOURCEID|TARGETID have anything at all to do with 
the enhancement to the VTAM command processor or was that a "red herring"?

Chris Mason

On Fri, 5 Aug 2011 14:32:22 -0400, Barkow, Eileen <[email protected]> wrote:

>I got the answer from IBM - there is a NETVIEW AUTHCHCK parm in CNMSTYLE which 
>is currently set to
>SOURCEID instead of TARGETID as it used to be.
>This causes the security checking to be invoked against the invoking user and 
>not the userid who is running the task.
>
>Thanks to all who responded.
>
>-----Original Message-----
>From: IBM Mainframe Discussion List [mailto:[email protected]] On Behalf Of 
>Barkow, Eileen
>Sent: Friday, August 05, 2011 11:03 AM
>To: [email protected]
>Subject: Netview security problem
>
>Would anyone know what is causing the error below?
>I am trying to researchit  but I am not very familiar with Netview internals 
>and parameters and need a fast solution.
>The RACF group says that nothing was changed on this lpar and the Netview 
>programmer is not sure about
>any changes to security.
>I think that the error started happening when we went to  Netview 5.4 from 
>either 5.3 or 5.2
>The clist named NEWCOPYR is invoked from userid  XXXX0018 via a job stream 
>issuing commands from a program (via  svc 34).
>The user is not authorized to issue any MVS commands directly but has always 
>been allowed to invoke clists
>(via * for automation Netview) from the program.
>
>The NEWCOPYR clist routes the commands to an autoperator (DPCINTAA)  for 
>processing -
>The ROUTE and other commands have always run under the auto-operator's id 
>which has authority to issue them -
>now they are  trying to be run under the invoking users id (XXXX0018).
>
>Is there some parameter in Netview to control this so that the commands just 
>run under the userid of the Netview operator and
> not the invoking user?
>
>           Thanks list
>
>JOB23281 00000290  *NEWCOPYR CICSSAP3 FINRPAD D NO DOFD N N N N    N RMD
>10:25:54.47 DPCINTAA 00000290  ROUTE DOFD,F CICSSAP3,CWTO NEWCOPY01: NEWCOPY
>                               USERID XXXX0018
>10:25:54.47 DPCINTAA 00000090  IEE345I ROUTE    AUTHORITY INVALID, FAILED BY
>10:25:54.47          00000090  ICH408I USER(XXXX0018 ) GROUP(XXD00   ) NAME(A
>                 041 00000090    MVS.ROUTE.CMD.DOFD CL(OPERCMDS)
>                 041 00000090    INSUFFICIENT ACCESS AUTHORITY
>                 041 00000090    FROM MVS.** (G)
>                 041 00000090    ACCESS INTENT(READ   )  ACCESS ALLOWED(NONE

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to