Diagnosing XCOM message XCOMM0463E ERROR SETTING REMOTE USER ID: TRUSTED ACCESS DENIED
search cancel

Diagnosing XCOM message XCOMM0463E ERROR SETTING REMOTE USER ID: TRUSTED ACCESS DENIED

book

Article ID: 420682

calendar_today

Updated On:

Products

XCOM Data Transport - z/OS

Issue/Introduction

This message may be received by XCOM in any platform when trying to initiate a "trusted transfer" with XCOM in MVS

The XCOM partner requests a trusted transfer by specifying TRUSTED=Y in the transfer parameters. 

The message is received in a 'FMH7 header' which in the XCOM protocol, is used to notify the partner of errors.

For example, for an MVS partner initiating a trusted transfer to MVS, the messages would be:

XCOMM0127E FMH7 SENSE 08890000 - GDS MSG FOLLOWS              
XCOMM0463E ERROR SETTING REMOTE USER ID: TRUSTED ACCESS DENIED

Cause

The message means that the MVS partner that receives the request has been unable to find a trusted definition that matches the parameters of the incoming transfer

The information considered from the incoming transfer is:

  • The IP name or IP address of the partner
  • The userid that initiated the request 

The IP name or address is used to assign an XCOM destination definition to the partner that initiates the transfer

Then the userid is matched against the userids specified in the TRUSTID= entries (if any) coded in the destination definition

If a match is found, the trusted transfer is accepted. Otherwise the transfer is rejected with message XCOMM0463E

If the matched TRUSTID= entry contains the optional GROUPID parameter, this value is used as the userid for the transfer. Otherwise the userid presented by the partner is used.

Resolution

  1. Look for destination members (having TYPE=DEST as their first non-comment statement) in the library chain allocated in XCOMCNTL DD in the JCL of the XCOM started task
  2. The one selected for the transfer (if any) will have the IP name or address of the partner in its IPNAME parameter
  3. Ensure that this destination is enabled (message (message XCOMM0559I member_name    ENABLED  SUCCESSFULLY) in XCOMLOG DD during startup.
  4. See whether the userid presented by the partner matches any TRUSTID entry in the destination member

NOTE: It is possible to dynamically enable and disable destinations by sending ENABLE and DISABLE commands to the XCOM started task. It is also possible to display the definition of a destination using the LIST command. All the commands are documented in Using the MODIFY commands section in he XCOM documentation

If any edit is needed to a destination member, it has to be disabled and enabled so that XCOM loads the definition again. The change takes effect immediately