All,

 

In the middle of doing a maintenance cycle, and came across the APAR
summarized below which is currently running in our Sandbox.   It added
new security checking at the Unix File system level - FSACCESS resource
class.   If you also use CA-TopSecret as your ESM, then you may want to
avoid this new function PTF for now.   We have it on, along with
supporting TSS fixes, and things just are not  yet ready for primetime
in the TSS arena.   CA is working on it, but we may just back this PTF
off for now to avoid the headaches.  

 

Initial symptoms we were seeing was FileSystem mounts failing at IPL due
to "No Access"(BPXPRMxx mounts).   Got past that with some new security
definitions, but still getting sporadic no access situations with some
OMVS tasks, and 0C4's in CA-TSS modules in the Netview address space.

 

APAR Identifier ...... OA35970      Last Changed ........ 11/10/04

  NEW FUNCTION - NEW ACCESS CONTROL CHECK USING FSACCESS

  CLASS PROFILE.  SEE ALSO OA35973 AND OA35974.

  Symptom ...... NF FUNCTION          Status ........... CLOSED  UR1

  Severity ................... 4      Date Closed ......... 11/09/06

  Component .......... 5695SCPX1      Duplicate of ........

  Reported Release ......... 770      Fixed Release ............ 999

  Component Name OPENMVS SYS SRV      Special Notice       ATTENTION

  Current Target Date ..11/09/30      Flags

  SCP ...................                            NEW FUNCTION

  Platform ............

 

  Status Detail: SHIPMENT - Packaged solution is available for

                            shipment.

  PE PTF List:

  PTF List:

  Release 770   : UA62046 available 11/09/21 (F109 )

  Release 780   : UA62047 available 11/09/21 (F109 )

 

  Parent APAR:

  Child APAR list:

 

  ERROR DESCRIPTION:

  This APAR provides a new function to enforce access control

  check on z/OS UNIX zFS file systems using the new

  RACF FSACCESS class profile.

 

 

 

_________________________________________________________________

Dave Jousma

Assistant Vice President, Mainframe Services

[email protected]

1830 East Paris, Grand Rapids, MI  49546 MD RSCB2H

p 616.653.8429

f 616.653.2717

 

This e-mail transmission contains information that is confidential and may be 
privileged.
It is intended only for the addressee(s) named above. If you receive this 
e-mail in error,
please do not read, copy or disseminate it in any manner.  If you are not the 
intended 
recipient, any disclosure, copying, distribution or use of the contents of this 
information
is prohibited. Please reply to the message immediately by informing the sender 
that the 
message was misdirected. After replying, please erase it from your computer 
system. Your 
assistance in correcting this error is appreciated.




----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to