All,
In the middle of doing a maintenance cycle, and came across the APAR
summarized below which is currently running in our Sandbox. It added
new security checking at the Unix File system level - FSACCESS resource
class. If you also use CA-TopSecret as your ESM, then you may want to
avoid this new function PTF for now. We have it on, along with
supporting TSS fixes, and things just are not yet ready for primetime
in the TSS arena. CA is working on it, but we may just back this PTF
off for now to avoid the headaches.
Initial symptoms we were seeing was FileSystem mounts failing at IPL due
to "No Access"(BPXPRMxx mounts). Got past that with some new security
definitions, but still getting sporadic no access situations with some
OMVS tasks, and 0C4's in CA-TSS modules in the Netview address space.
APAR Identifier ...... OA35970 Last Changed ........ 11/10/04
NEW FUNCTION - NEW ACCESS CONTROL CHECK USING FSACCESS
CLASS PROFILE. SEE ALSO OA35973 AND OA35974.
Symptom ...... NF FUNCTION Status ........... CLOSED UR1
Severity ................... 4 Date Closed ......... 11/09/06
Component .......... 5695SCPX1 Duplicate of ........
Reported Release ......... 770 Fixed Release ............ 999
Component Name OPENMVS SYS SRV Special Notice ATTENTION
Current Target Date ..11/09/30 Flags
SCP ................... NEW FUNCTION
Platform ............
Status Detail: SHIPMENT - Packaged solution is available for
shipment.
PE PTF List:
PTF List:
Release 770 : UA62046 available 11/09/21 (F109 )
Release 780 : UA62047 available 11/09/21 (F109 )
Parent APAR:
Child APAR list:
ERROR DESCRIPTION:
This APAR provides a new function to enforce access control
check on z/OS UNIX zFS file systems using the new
RACF FSACCESS class profile.
_________________________________________________________________
Dave Jousma
Assistant Vice President, Mainframe Services
[email protected]
1830 East Paris, Grand Rapids, MI 49546 MD RSCB2H
p 616.653.8429
f 616.653.2717
This e-mail transmission contains information that is confidential and may be
privileged.
It is intended only for the addressee(s) named above. If you receive this
e-mail in error,
please do not read, copy or disseminate it in any manner. If you are not the
intended
recipient, any disclosure, copying, distribution or use of the contents of this
information
is prohibited. Please reply to the message immediately by informing the sender
that the
message was misdirected. After replying, please erase it from your computer
system. Your
assistance in correcting this error is appreciated.
----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html