When I try to list RACF objects (groups permissions and users) from an LDAP browser, for example, JXplorer, the list fails with LDAP : error code 49 - ICH408I and CSV025I are seen
search cancel

When I try to list RACF objects (groups permissions and users) from an LDAP browser, for example, JXplorer, the list fails with LDAP : error code 49 - ICH408I and CSV025I are seen

book

Article ID: 21619

calendar_today

Updated On:

Products

ACF2 ACF2 - DB2 Option ACF2 for zVM ACF2 - z/OS ACF2 - MISC 24X7 High-Availability Manager for DB2 for z/OS Batch Processor Compile QQF Data Compressor for DB2 for z/OS CA Unicenter NSM RC/Update for DB2 for z/OS DB2 TOOLS- DATABASE MISC PanApt PanAudit Top Secret Top Secret - LDAP

Issue/Introduction

 

When I try to list RACF objects (groups, permissions and users) from an LDAP browser, for example, JXplorer, the list fails with LDAP: error code 49 - ICH408 and CSV025I.

Messages similar to these may be seen regarding the RACF address space userID.

BPXM023I (CALDAP) 
LDP4904I CA LDAP Server is processing a SEARCH CLASS(USER) for all
USERS per a request from IP=###.###.###.##:nnnn on behalf of xxxxxx
ICH408I USER(RACF ) GROUP(STCGROUP) NAME(STC RACF ) 
SETROPTS CL(PROGRAM )
INSUFFICIENT ACCESS AUTHORITY
ACCESS INTENT(READ ) ACCESS ALLOWED(NONE )
CSV025I PROGRAM CONTROLLED MODULE SETROPTS NOT ACCESSED, USER UNAUTHORIZED
IEF196I CSV025I PROGRAM CONTROLLED MODULE SETROPTS NOT ACCESSED, USER
IEF196I UNAUTHORIZED
CSV028I ABEND306-30 JOBNAME=RACF STEPNAME=RACF
IEF196I CSV028I ABEND306-30 JOBNAME=RACF STEPNAME=RACF

This can be resolved by setting the TRUSTed attribute to the RACF subsystem address space profile.

 

 

Environment

Release:
Component: ACFLDP

Resolution

Within the RACF_UTF Backend, the use of the R_Admin callable service requires that you assign the TRUSTed attribute to the RACF subsystem address space profile. A TRUSTED address space is treated as part of the trusted computing base. Contact your security administrator for implementation.

 

Additional Information

See the IBM z/OS  MVS Initialization and Tuning Reference z/OS  section "Assigning the RACF TRUSTED Attribute" for more information.