On 1/29/2019 12:27 AM, Barbara Nitz wrote:
I have a strange issue with the ISPF main (first) panel. I have added 
permission to view the APF list:

pe ISFCMD.ODSP.APF.* cl(sdsf) id(grpname) ac(r)

and I have refreshed the raclisted sdsf class. I expected the APF command to 
show up in the ISPF main panel once I call ISPF. It does NOT show up. 
LOGOFF/LOGON (just to be safe) did not help, either.

A user in grpname can issue the APF command without any error. Once that user 
leaves the APF command, it is shown correctly on the primary panel. Leaving and 
reentering SDSF produces the same behavior: Only when the user has already 
issued the APF command is it getting shown.

z/OS is 2.3, the behavior occurs on different sysplexes at different 
maintenance levels. The latest level is RSU1812. No ICH408I when running with 
sectrace on.

To make matters even more strange: My colleague had used the APF command 'at 
work' successfully (not seeing the command on the main panel, but being able to 
execute it). Then, from home, she got 'authorization error', the same one one 
gets when issuing a command that one isn't authorized for. We even used three 
different 3270 emulators, just to prove that it is not an emulator issue.

Does anybody have any idea what I might be doing wrong with the definition? It 
might stare me in the face and I just don't see it.


Barbara,

I've had a very hard time enabling the new commands in SDSF. Issue the TRACE ON;TRACE 80 command, then your failing APF command, then TRACE OFF. Do a DA OJOB, and a ? in front of the user's TSO session, and look at the ISFTRACE DD. The RACF profiles are listed in there and you should see the profile you're failing on.

Mit freundlichen Grüßen,
Tom Conley

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

Reply via email to