We have a console command "V XCF,ABC,OFFLINE" being issued from a console defined with LOGON=AUTO and are getting message "IEE345I V AUTHORITY INVALID, FAILED BY MVS". How can I run a SECTRACE to determine what RACROUTE calls are being issued?

book

Article ID: 52668

calendar_today

Updated On:

Products

CA ACF2 CA ACF2 - DB2 Option CA ACF2 for zVM CA ACF2 - z/OS CA ACF2 - MISC CA PanApt CA PanAudit

Issue/Introduction

Description:

With the operand LOGON(AUTO) in SYS1.PARMLIB(CONSOLxx) each console will automatically be logged on at IPL time with the userid which is the same as the console name. The RACROUTE REQUEST=AUTH CLASS=OPERCMDS call for commands issued from these consoles will be against a userid of "+CONSOLE" and JOBNAME "CONSOLE" in the racroute header information, rather than the actual console logonid that was automatically logged on. The actual console userid is contained in the ACEE parameter of the call itself.

Solution:

Since the console userid is actually only specified in the ACEE parameter of the call itself for consoles automatically logged on with the SYS1.PARMLIB(CONSOLxx) LOGON=AUTO operand the ACF2 SECTRACE should be set as follows without the USERID parameter. The actual console userid that was logged on can be found if FORMAT=DUMP is specified in the SECTRACE command for jobname CONSOLE.

Example:

ST SET,ID=TEST,TYPE=SAFP,DEST=CONSOLE,FORMAT=DUMP,JOBNAME=CONSOLEnn CAS21A0I SPECIFY RACROUTE PARAMETERS, CANCEL, OR ENDR nn,request=auth,class=opercmds,endnn CAS2100I Continue SECTRACE specification, CANCEL, or ENDR nn,end

The following sample SECTRACE output shows the actual console userid CONSOLEA in the ACEE:

SMFID= SYS1         TOD= 08:20:46.53    TRACEID= TEST       USERID= +CONSOLEJOBNAME= CONSOLE    ASID= 0009          PGM= IEECB92S       CURR RB= IEECB92SSFR/RFR= 0/0:0      MODE= TASK          APF= AUTHORIZED     LOCKS= NONESAFDEF= OPERCMD  GSO      MODE= GLOBAL  RACROUTE REQUEST=AUTH,REQSTOR='IEE3503D',SUBSYS='CONSOLE',         CLASS='OPERCMDS',RELEASE=1.9,STATUS=NONE,ACEE=,ATTR=READ,         DSTYPE=N,DECOUPL=YES,ENTITY=('MVS.DISPLAY.JOB'),FILESEQ=0,         GENERIC=ASIS,LOG=ASIS,LOGSTR='D A,L',MSGRTRN=YES,MSGSP=1,         MSGSUPP=YES,TAPELBL=STD,WORKA=ACEE     DATA AREA FOLLOWS00060550 +000  C1C3C5C5 FF0001D0 03000000 7F230830  *ACEE........"...*00060560 +010  00000000 08C3D6D5 E2D6D3C5 FC115C40  *.....CONSOLEA.* *00060570 +020  40404040 40400100 0009119F 00000000  *      ..........*

Environment

Release:
Component: ACF2MS