TSS0207E Insufficient Authority for Function Error in CA LDAP
search cancel

TSS0207E Insufficient Authority for Function Error in CA LDAP

book

Article ID: 265731

calendar_today

Updated On:

Products

Top Secret for z/OS LDAP SERVER FOR Z/OS Top Secret for z/VM Top Secret for z/VM

Issue/Introduction

This article addresses the TSS0207E INSUFFICIENT AUTHORITY FOR FUNCTION error encountered when attempting to read from or update the Top Secret Security File through CA LDAP.

 

Environment

  • Product: CA Top Secret for z/OS
  • Component: CA LDAP Server for z/OS
  • Release: 16.0

Cause

The user performing the LDAP operation lacks the necessary TSS ADMIN privileges to execute the requested command against the Top Secret Security File. CA LDAP enforces the same administrative privilege restrictions as those found in BATCH, CICS, or TSO environments.

Resolution

To resolve this issue, ensure the user account performing the LDAP operation is granted the required TSS ADMIN privileges.

  1. Verify the user's current administrative authority.
  2. Grant the necessary administrative authority required for the function.

For more information on administering command functions and granting administrative authority, see the Broadcom TechDocs: Grant Administrative Authority.

Error Log Details:

[05/09!14:46:28.011362!1A44580000000003~ conn=1014 op=5 SEARCH RESULT tag=101 err=80 nentries=1 text=LDP2004E Error issuing command with R_Admin, function=1, SAF=8, RACF=16, reason=8(0001) TSS0207E INSUFFICIENT AUTHORITY FOR FUNCTION