Is it necessary to create a new SECFILE if Next Available is close to Last Available acid number?
search cancel

Is it necessary to create a new SECFILE if Next Available is close to Last Available acid number?

book

Article ID: 91824

calendar_today

Updated On:

Products

Top Secret Top Secret - LDAP

Issue/Introduction

Is it necessary to create a new SECFILE if the Next Available acid number and Last Available acid number are very close or are the same number?  

Environment

Release:
Component: TSSMVS

Resolution

When a security file is created, the ACIDs fill the ACID index entries starting from one until all ACIDs have a number. Then any new ACIDs take the next available number. When the Last available number is taken then the NEXT Available and LAST Available acid numbers will be the same and they will remain that way. But that does not mean that you are out of acid index entries, it only means that you have chronologically used them at one time. Each time you delete an acid it opens an available acid index but those do not get filled until the LAST Available and NEXT available numbers have been used. 

What you need to look at is:
Acid index entries allocated: xxx,xxx
and compare that to:
Acid index entries defined: xx,xxx

The Acid index entries allocated are the number of acids you can possibly have on the secfile and the Acid index entries defined is the number of acids currently defined.  If there is a about 25% or more entries allocated than defined you should be fine unless there are plans to create a very large number of acids for some reason such as a merger or consolidation of sites.