ACF2 validations using Roles are sometimes incorrect after role changes and F ACF2,NEWXREF,TYPE(ROL)
search cancel

ACF2 validations using Roles are sometimes incorrect after role changes and F ACF2,NEWXREF,TYPE(ROL)

book

Article ID: 231974

calendar_today

Updated On:

Products

ACF2 - z/OS

Issue/Introduction

After role records have been changed and an F ACF2,NEWXREF.TYPE(ROL) is issued,
A user does not pickup the new role setup - violations still show the old role list for the user .  

                                

Environment

Release : 16.0

Component : ACF2 for z/OS

Resolution

When Role records are updated the F ACF2,NEWXREF,TYPE(ROL)
sub-command is required,
If the ROLES sub-command is issued, it  may show different roles
that a user is connected to than what the user is actually running with.

This is because the newxref command only changes in-storage tables, 
It does not dynamically change the roles of a logged on user.
Also, the ACCESS sub-command may show incomplete data.
This can be resolved by issuing the F ACF2,NEWUID command to rebuild
the ACCESS sub-command in-storage tables.