On Thu, 28 Apr 2016 12:22:17 -0500, Paul Gilmartin <[email protected]> wrote:
>On Thu, 28 Apr 2016 12:01:17 -0500, Mark Zelden wrote: > >>I'm applying z/OS 2.1 RSU1603 and came across this PTF. Is anyone running >>with >>it in production and has it caused you any grief? This seems to change a >>behavior >>that has been around "forever", so it concerns me a bit even though there >>is a work around by defining a special RACF profile in the Facility class. >> >> ... >> Now, with this PTF, the RACF authority check is performed using >> the ALIAS, PATH, or ALTERNATEINDEX name. >> >WTF!? Does this mean that I will be able to DEFINE an ALIAS in a profile >in which I have access, to a dataset to which I have less authority, thereby >escalating my authority? Will DEFINE ALIAS verify and enforce that I >am not so escalating my authority to the RELATED data set? If an administrator >subsequently revokes my authority to the RELATED data set, will my authority >to the ALIAS be correspondingly adjusted? > >??? > No, it doesn't mean that. Checking will still be done on the real name. Read carefully about "the likely outcome". Best regards, Mark -- Mark Zelden - Zelden Consulting Services - z/OS, OS/390 and MVS ITIL v3 Foundation Certified mailto:[email protected] Mark's MVS Utilities: http://www.mzelden.com/mvsutil.html Systems Programming expert at http://search390.techtarget.com/ateExperts/ ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
