Elardus, I have but one LPAR, we do not use RRSF, and we have no exits. We do use RRDF to allow for some password synchronization for those users who have multiple logons. This ID did not have a PEER, however.
I tried a few experiments with the IRRADU00 utility. I haven't found any reference to this user ID yet, but will continue. Thanks for that hint - there are more tools to audit RACF than I know about. And yes, really, no one modified SMF, but thanks for asking. Regards, Greg -----Original Message----- From: IBM Mainframe Discussion List [mailto:[email protected]] On Behalf Of Elardus Engelbrecht Sent: Wednesday, August 07, 2013 11:51 AM From what LPARs are you collecting your records? Do you have RRSF? Do you have an IRREVX01 exit (RACF command processor exit) Do you have any password exit? Alternatively, rather use IRRADU00 for your audits. That will catch new things not possible with RACFRW. <snip> Groete / Greetings Elardus Engelbrecht ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
