On Mon, 16 Mar 2015 13:26:02 -0500, Walt Farrell wrote:
>>
>>... is now impacted in that calling IEBCOPY causes his program to lose 
>>authorization/
>>ABEND/whatever.
>
>Not true, gil. A program running APF-authorized does not lose authorization by 
>calling an AC(0) module. It keeps running authorized, assuming, of course, 
>that the AC(0) module came from an APF-authorized library.  ..
>
I stand very corrected.  I thought I used to know that.

But let me try again.  IEBCOPY has been demoted from "APF Authorized" to
"Module residing in an authorized library, marked AC(0), so not designed to
be invoked authorized."  This somewhat shifts the burden of parameter
validation from IEBCOPY itself to any authorized caller.

Charles could save himself some doubt by marking one program he mentioned
AC(0) (for z/OS 1.13 and higher).

-- gil

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to