IBM Support

PH08497: MESSAGE ICH408I IS NOT GENERATED WHEN USER LACKS ACCESS TO PROFILE PREFIX IN APPL CLASS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When the safCredentials configuration specifies
    suppressAuthFailureMessages, and the value is set to false,
    Liberty will allow SAF to print certain messages (such as
    ICH408I) when an authorization failure occurs.  In the case
    where a user does not have access to the profile prefix in
    the APPL class, an ICH408I message is not printed.  There
    will be a CWWKS2907E message in the message log for the
    Liberty server, indicating the user who lacks access.
    However this message does not give the SAF administrator the
    information that they need to assign the correct access to
    the user.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server Liberty for z/OS                     *
    ****************************************************************
    * PROBLEM DESCRIPTION: Message ICH408I is not printed when a   *
    *                      user does not have access to the APPLID *
    *                      in the APPL class                       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    A user who wishes to use the WLP z/OS System Security Access
    Domain (WZSSAD) in Liberty requires read access to the APPLID in
    the SAF APPL class.  When the suppressAuthFailureMessages is set
    on the safCredentials configuration in server.xml, Liberty
    should force SAF to print an ICH408I message when an
    authorization failure occurs trying to access the WZSSAD.  This
    requires a second RACROUTE FASTAUTH call with message
    suppression turned off, to force the ICH408I message.  The
    second RACROUTE call was being made with an incorrect ACEE.  The
    second RACROUTE call is not used in the authorization decision;
    it is only used to print the ICH408I message.
    

Problem conclusion

  • The second call to RACROUTE FASTAUTH is changed to use the
    correct ACEE when forcing message ICH408I for a user who does
    not have access to the APPLID in the APPL class.
    
    The fix for this APAR is currently targeted for inclusion in fix
    pack 19.0.0.2.  Please refer to the Recommended Updates page for
    delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH08497

  • Reported component name

    LIBERTY PROF -

  • Reported component ID

    5655W6514

  • Reported release

    CD0

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-02-12

  • Closed date

    2019-02-13

  • Last modified date

    2019-02-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    LIBERTY PROF -

  • Fixed component ID

    5655W6514

Applicable component levels

  • RCD0 PSY

       UP

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Platform":[{"code":"PF054","label":"z Systems"}],"Version":"CD0","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
17 June 2020