Assuming all your group SYS1 users don't also have the OPERATIONS
attribute, there is a separate profile (don't have my manuals handy)
which can be used to just to grant the authority to define aliases in
the master catalog. Perhaps they have access to that.
Crispin Hugo wrote:
I have a RACF profile defined for the master catalog CATALOG.Z17.MASTER
which has a UACC of READ with group TSG in the access list with ALTER. The
profile is owned by group TSG. The profile is defined as Generic although it
is the fully qualified name. Group SYS1 is not mentioned at all in the
profile.
It seems however that any userid that is in group SYS1 can still UPDATE the
master catalog. For example a DEFINE ALIAS works from any userid or task
associated with a group SYS1 user. Is this set up as a standard? I can't
find anything obvious in the documentation.
Thanks
Crispin Hugo Systems Programmer, Macro 4
http://www.macro4.com/
Macro 4 plc, The Orangery, Turners Hill Road, Worth, Crawley, RH10 4SS
...
--
Joel C. Ewing, Fort Smith, AR [EMAIL PROTECTED]
----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html