View previous topic :: View next topic
|
Author |
Message |
madsanchez
New User
Joined: 27 Jul 2023 Posts: 8 Location: United States
|
|
|
|
Hi all, I'm looking for some insight on an issue our team ran into from a PuTTY user.
This team was in the process of getting setup for VSAM service in Production and getting an error from this particular user ID (let's call him U000000).
We looked at what group U000000 was in, and granted that group ALTER access to the data set profile VSAMSVCT.** in RACF. However, U000000 still received the same error.
We checked u000000 OMVS and home directory, and nothing looked out of the ordinary.
Any advice? [img][/img] |
|
Back to top |
|
|
Pedro
Global Moderator
Joined: 01 Sep 2006 Posts: 2594 Location: Silicon Valley
|
|
Back to top |
|
|
vasanthz
Global Moderator
Joined: 28 Aug 2007 Posts: 1744 Location: Tirupur, India
|
|
|
|
If I am not wrong,
The su -s - VSAMSVCT
switches the current user to VSAMSVCT. How would granting access to a dataset profile make the current user a surrogate user to VSAMSVCT?
I think you have to follow the steps here to setup VSAMSCVT as surrogate ID to U000000.
www.ibm.com/docs/en/sia?topic=ac-surrogate-user-id-2 |
|
Back to top |
|
|
madsanchez
New User
Joined: 27 Jul 2023 Posts: 8 Location: United States
|
|
|
|
We tried that yesterday afternoon. We added U000000's group profile (lets call it group ABC#123) to Class Surrogate of BPX.SRV.VSAMSVC* and gave them READ access.
We also added group ABC#123 ALTER access to dataset profile VSAMSVCT.**
A part of me wonders if this is a user error on behalf of the PuTTY user? Because we defined the correct SURROGAT profile (at least I think we did? lol)
This forum posting gave me a little more context into that thought - www.ibmmainframeforum.com/mainframe-security/topic10013.html |
|
Back to top |
|
|
vasanthz
Global Moderator
Joined: 28 Aug 2007 Posts: 1744 Location: Tirupur, India
|
|
|
|
spit balling here,
Have you checked if VSAMSCVT has an OMVS segment? |
|
Back to top |
|
|
Pedro
Global Moderator
Joined: 01 Sep 2006 Posts: 2594 Location: Silicon Valley
|
|
|
|
re: "We looked at what group U000000 was in"
Please confirm that your site has list-of-groups checking enabled.
For problem determination, consider permitting the user directly rather than the group. |
|
Back to top |
|
|
|