JESSPOOL ACCESS granted access for a user's high level qualifier even though they are not authorized.
search cancel

JESSPOOL ACCESS granted access for a user's high level qualifier even though they are not authorized.

book

Article ID: 48952

calendar_today

Updated On:

Products

Top Secret Top Secret - LDAP Top Secret - VSE

Issue/Introduction

USERA has the following JESSPOOL permissions:

TSS PERMIT(USERA) JESSPOOL(xxxx.USERA) ACCESS(NONE) 

which should deny access, but it is still granted access to the resource.

Environment

Release:
Component: AWAGNT

Resolution

With the JESSPOOL resource class, if the second high level qualifier is the acid getting the security check, it will always be granted access regardless of what permissions are set.

This is not a bug, but how the code was written.

Users should always be able to get at their own JESSPOOL resources. Otherwise, abends could occur in JES.

This is not just done by Top Secret but other z/OS security products.