Here is one for Alan, but it looks like Chuckie might have a comment,
too.

During our plight with TCPNJE, we tried routing the jobs through an
intermediate MVS system. The jobs reached their destination and ran. The
destination MVS system then tried to send the results back by the
reverse route, The output files reached the intermediate MVS system and
RACF stepped up to the plate. The files were allowed to go no farther
because there is a userid on the MVS system that matches the VM userid
for which the files were tagged. I know that this is MVS RACF, but maybe
Alan has the answers to these questions:

1.      Is that normal behavior for RACF? Would RACF on VM do the same
thing?
2.      Why is RACF on MVS even looking at the userid of files that are
tagged for another node? It is the destination node that should be
looking after the security for the files. RACF on MVS has no idea what
rules are in effect on the destination system. By definition, it is
remote and possibly using a different ESM.

Regards, 
Richard Schuh 


Reply via email to