IBM Support

OA45277: SMB WINDOWS CLIENT AUTHENTICATION FAILURE ACCESS DENIED

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • A problem exists where additional sessions requested from the
    same physical windows client(ip address) result in access denied
    being returned from the zOS SMB server to the client.
    
    
    The extracted SMB trace will show the following:
    
    (003 09:34:36.323858) >>>-SMB-sess=27042298 refct=00000002
    csp=27292800 com=x73 uid=x0000 tid=x0000 s=23
    ip=140.170.185.183..59798
    .
    .
    (003 09:34:36.323905) KML Active user exists already return
    deny  and cleanup up
     (003 09:34:36.323906) TSession::Using: usp=27042298
    refct=00000003 after hold
     (003 09:34:36.323906) smb_sesssetupX - Close TSMBsess set from
    failed getargsextened
     (003 09:34:36.323906) SMB_HANDLER(smb_sesssetupX) Value of
    smb_com2 4 =117
     (003 09:34:36.323907) CleanupAndSendSetupResponseExtended rc=5
     (003 09:34:36.323907) SMB_HANDLER(smb_sesssetupX) sending error
    response, rc=5
    .
    .
    (003 09:34:36.323953) <<<-SMB-sess=27042298 refct=80000001
    csp=27292800 com=x73 uid=x0000 tid=x0000 err=(1,5) RESP
    

Local fix

  • na
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of the z/OS Distributed File       *
    *                 Service SMB Server.                          *
    ****************************************************************
    * PROBLEM DESCRIPTION: When attempting to setup multiple       *
    *                      user sessions from a single windows     *
    *                      server, only one session is allowed     *
    *                      access at any one time .                *
    ****************************************************************
    * RECOMMENDATION: APPLY PTF                                    *
    ****************************************************************
    Authentication for multiple user sessions issued from a Windows
    Server using encrypted password support will only allow one
    authenticated session at a time. When additional user session
    authentication requests are generated, the current authenticated
    session will be torn down allowing for the new session
    session to authenticate.
    

Problem conclusion

  • A code path in the encrypted password support was restricting
    the use of multiple user authentications sessions. Additional
    code was added to allowing the sessions to authenticate.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA45277

  • Reported component name

    DFS FILE SERVIC

  • Reported component ID

    569694200

  • Reported release

    410

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2014-05-21

  • Closed date

    2014-06-27

  • Last modified date

    2016-12-08

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UA74002

Modules/Macros

  • IOEDFSKN
    

Fix information

  • Fixed component name

    DFS FILE SERVIC

  • Fixed component ID

    569694200

Applicable component levels

  • R410 PSY UA74002

       UP14/07/31 P F407

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"410","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":null,"label":null},"Product":{"code":"SG19O","label":"APARs - MVS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"410","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
08 December 2016