OK, got past previous error by setting owner/group of /var/lpp/zosmf/ to 
IZUSVR1/IZUADMIN. Different problem now, but not able to provide details at the 
moment. 

.
.
.
J.O.Skip Robinson
Southern California Edison Company
Electric Dragon Team Paddler 
SHARE MVS Program Co-Manager
323-715-0595 Mobile
626-302-7535 Office
[email protected]

-----Original Message-----
From: IBM Mainframe Discussion List [mailto:[email protected]] On Behalf 
Of Jesse 1 Robinson
Sent: Saturday, April 16, 2016 12:29 PM
To: [email protected]
Subject: Setting up z/OSMF under 2.1

I'm trying to get z/OSMF working under 2.1. We ran it in a limited way for 
years before 2.1, but the pioneering z/OSMF guy is gone, and I'm trying to 
revive it. In particular I'm getting a RACF error starting the second z/OSMF 
task IZUSVR1. I get this:

SCEUJI04I STC  IZUSVR1  STARTED    11.29.43 16 APR 16
IEF403I IZUSVR1 - STARTED - TIME=11.29.43 ICH408I USER(IZUSVR  ) 
GROUP(IZUADMIN) NAME(ZOSMF STARTED TASK U)
  /var/zosmf/configuration/configuration_planned.cfg
  CL(DIRACC  ) FID(C2E2F3F0F0F605710000000000020001)
  INSUFFICIENT AUTHORITY TO OPEN
  ACCESS INTENT(-W-)  ACCESS ALLOWED(OTHER      ---)
  EFFECTIVE UID(0000900700)  EFFECTIVE GID(0000900698)
SCEACT01I STEP ZPARM    IZUSVR1    CPU 00:00:00.01 CC=0016

IIRC DIRACC is phantom error because there is no such class. Something is 
defined wrong. The ZFS containing /var/zosmf/ is 'SPP.IZU.ZFS', covered by RACF 
profile 'SPP.IZU.ZFS*'. Group IZUADMIN has ALTER access to this profile.

I'm a total bumbler when it comes to USS authorization. What else do I need to 
look at? P.S. cannot post to RACF-L because the confirmation email for my 
current sce.com userid gets blocked by corporate policy (Sender field is blank 
as if spam).

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to