ACF2 message in CICS: ACFAE918 Logonid suspended because of security violations
search cancel

ACF2 message in CICS: ACFAE918 Logonid suspended because of security violations

book

Article ID: 203960

calendar_today

Updated On:

Products

ACF2 ACF2 - z/OS ACF2 - MISC

Issue/Introduction

This is from the CICS log.  This user got the same error 3 times and on the third time got suspended.

VIO WTO: ACFAE900 LID=logonid TERM=source RESOURCE=TRANS NAME=transaction               
VIO WTO: ACFAE913 ACF2 security violation: Source=source Access=V               
VIO WTO: ACFAE918 Logonid logonid suspended because of security violations       

Any idea which parm would be causing this behavior in CICS?

Environment

Release : 16.0

Component : CA ACF2 for z/OS

Resolution

The SUSPEND parameter specifies the conditions under which logonid suspension occurs. ACFM can modify this parameter.
The keywords that can be used with the SUSPEND parameter are:
 
SUSPEND Password=YES|NO
                   Rule=YES|NO
 
Keyword Descriptions
Password=YES|NO
Specifies if users are suspended during sign-on if the password violation count reaches the established threshold.
 
YES-Indicates that the user is considered suspended during sign-on if the password or password phrase violation count reaches the threshold established by the PASSLMT field of the host system GSO PSWD record. Also, the user is considered suspended if the number of password or password phrase violations accumulated in the current session count reaches the threshold established by the lower of the CICS interface OPTION MAXVIO parameter or the GSO PSWD record PASSLMT field. This happens only during password reverification. The current session count is set to zero after the sign-on has been completed. This information is not sent back to CA ACF2 for z/OS when sign-off is performed. Also, CA ACF2 for z/OS sets the SUSPEND field in the logonid record.
 
NO-Specifies that suspension does not occur for password or password phrase errors.
 
Rule=YES|NO
Specifies if users are suspended during resource validation if the violation count reaches the established threshold.
 
YES-Specifies that the user is considered suspended during resource validation if the violation count reaches the threshold established by host system controls.
 
NO-Indicates that suspension does not occur for violations.

Additional Information

For more information on the ACF2/CICS parameters, see CICS Interface Parameters in the CA ACF2 for z/OS documentation.