When executing the sesu command with a user identified by PAMSC (who belongs to an authorized group), the request fails with the following error in seaudit.
07 Aug 2026 03:34:05 D SURROGATE MyUser Read 63 3 USER.root /opt/CA/PAMSC/bin/sesu ServerName.Com
The rule "authorize SURROGATE ('USER.root') access(READ) xgid('MyGroup') via(pgm('/opt/CA/PAMSC/bin/sesu'))" was part of a properly deployed policy but was missing in the active seosdb database.
To restore functionality, follow these steps in order:
Verify and Add Missing Rules (Temporary Workaround) If immediate access is required, manually re-add the missing authorization rule to restore service. Example: authorize SURROGATE ('USER.root') access(READ) xgid('MyGroup') via(pgm('/opt/CA/PAMSC/bin/sesu'))
Redeploy the Policy Redeploy the affected policy to refresh the rules and align the active database with the deployment configuration.
Perform a Clean Database Initialization (If Necessary) If rules continue to go missing, or if DEVCALC errors persist after redeployment, the database may require a clean initialization: