Hello David, parm(new) did the trick! This bit of information must have been buried in all the RUCSA stuff that I skipped over because it doesn't apply to us. We don't have oa56180 applied yet, so that explains why the audit bit wasn't on in some cases.
I feel much more confident now to implement allowuserkeycads(no) and NUCLABEL ENABLE(IARXLUK2) to prevent usage on all systems. Thanks a lot, Barbara ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN