> This is WAD. You could use IRRRID00 (with a dummy SYSIN) to look out for > phantom PERMITs for those 2 groups just to make sure they're not there > anymore at all. I know. I should have remembered that I cannot delete a group that still has connections. As I said - I have done too much cleanup in the 1.13 IBM delivered ADCD RACF database, so my eyes must be crossing by now. Obsolete userids in racf resource classes are just a small thing. What really bothers me is that they apparently never got the memos what should have been done for a new release, so all old crap is still in there. (Cleanup? What's that? Can I eat that?) And when you get a new release of the ADCD, you get the same old crap again. At least this time around, I have everything in batch jobs, so the next cleanup to be done will be much easier (and faster). Add to that that I have given myself a crash course in being the RACF admin (never having had SPECIAL before), I think I can be forgiven for overlooking this. :-( <rant off>
Barbara ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN