Re: Auditing/Logging of DSFS activities

2025-07-11 Thread Robert S. Hansel
. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Thu, 10 Jul 2025 01:56:02 -0500 From:Roger Lowe Subject: Auditing/Logging of DSFS activities Trying to find a w

Re: setting up user and operator commands.

2025-07-03 Thread Robert S. Hansel
ontrol as discussed above. If a user deviates from using their own ID as the prefix, then perhaps restrict it what they can choose. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message-

Re: setting up user and operator commands.

2025-07-02 Thread Robert S. Hansel
k it wise to create MVS.MCSOPER.mcs/smcs-console-name profiles with no permissions so they can't be specified as their use may cause confusion. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original M

Re: setting up user and operator commands.

2025-06-30 Thread Robert S. Hansel
es without having to have an OPERPARM segment, including an AUTH setting. To use this operand, you need READ access to TSOAUTH resource CONOPER. There are no restrictions on what attributes you specify. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linke

Re: STC Userids

2025-06-12 Thread Robert S. Hansel
batch IDs. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Wed, 11 Jun 2025 09:05:33 -0400 From:Roberto Halais Subject: STC Userids I would like some feedback on

Re: Enabling the KDFAES encryption algorithm for the RACF Database

2025-04-28 Thread Robert S. Hansel
used ALTUSER PWCONVERT to immediately convert all passwords to KDFAES encryption. This does not, however, convert password phrases. The fallback is to activate the IRRUT200 backup that should have been take immediately prior to this event, which we've never had to do. Regards, Bob Robert S. H

Re: Enabling the KDFAES encryption algorithm for the RACF Database

2025-04-26 Thread Robert S. Hansel
g a system maintenance period. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.comm -Original Message- Date:Fri, 25 Apr 2025 19:11:31 + From:Jasi Grewal Subject: Enabling the KDFAES encryption alg

Re: RACF vs ISPF and controlled environment

2025-03-26 Thread Robert S. Hansel
access, which is all but impossible in an ISPF environment because so many different programs may be executed. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Tue, 25

Re: RACF and pathnames

2024-11-18 Thread Robert S. Hansel
names specified. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Sun, 17 Nov 2024 12:21:27 -0600 From:Paul Gilmartin Subject: RAC

Re: Suppressing a Very Specific Instance of ICH408I

2024-11-09 Thread Robert S. Hansel
he chaudit command to change the bits. For example, to remove failures auditing for execute/search, enter "chaudit x-f directory-name". To change the Owner audit bits if you are not the Owner, you must be Superuser. To change the Auditor bits, you much have RACF AUDITOR authority. Re

Re: Iin Defense of FTP. FUD rules

2024-09-28 Thread Robert S. Hansel
controlling the use of the JES-FTP interface. SERVAUTH EZB.FTP.sysname.ftpdaemonname.ACCESS.JES Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com

Re: help with REXX code reading RACF LU function

2024-09-09 Thread Robert S. Hansel
HI Lizette, Why not use the RACF database unload IRRDBU00 output instead? Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Sun

Re: AOPSTOP

2024-07-25 Thread Robert S. Hansel
aopstop via this group. I recommend aopsetup be rerun with the proper groups specified. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message

Re: TSO PREFIX change

2024-06-26 Thread Robert S. Hansel
Hi Juan, I've typically seen this done in TSO logon PROCs that execute a CLIST or REXX program that executes the PROFILE command to automatically reset the PREFIX for the user during each logon. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialis

Re: Data Set Commander Monitor (DSCMON) Access Authority

2024-06-26 Thread Robert S. Hansel
batch jobs to execute. Most installations do not generate daily/weekly reports on undefined users, so they go unnoticed unless the lack of an ID causes a security violation. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969

Re: Data Set Commander Monitor (DSCMON) Access Authority

2024-06-24 Thread Robert S. Hansel
HI Mike, (replying on both RACF-L and IBM-MAIN) I misunderstood what you were proposing in your initial reply on IBM-MAIN. I thought you were advocating setting default access of NONE on all Linklist libraries. I now understand you are advocating setting default access to READ, which I gene

Re: Data Set Commander Monitor (DSCMON) Access Authority

2024-06-22 Thread Robert S. Hansel
Hi Mike, Did you mean to say UACC(NONE) at the end of your second sentence? This isn't a 'best practice' I've heard of or necessarily agree with. At best, it would be a low priority and evaluated on a case-by-case basis. As you no doubt know, all the programs in the Linklist are available to ev

Re: Data Set Commander Monitor (DSCMON) Access Authority

2024-06-22 Thread Robert S. Hansel
ric to standards. > > > > ____________ > From: IBM Mainframe Discussion List on behalf of > Robert S. Hansel > Sent: Friday, June 21, 2024 7:50 AM > To: IBM-MAIN@LISTSERV.UA.EDU > Subject: Data Set Commander Monitor (DSCMON) Access Authority >

Data Set Commander Monitor (DSCMON) Access Authority

2024-06-21 Thread Robert S. Hansel
your replies. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 <http://www.linkedin.com/in/roberthansel> www.linkedin.com/in/roberthansel <http://www.rshconsulting.com/> www.

Re: SDSF and z/OS V2.5

2024-06-18 Thread Robert S. Hansel
statement parameter AUXSAF. See presentation above for details. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com

Re: RACF permission to INETD OTELNET port?

2024-06-18 Thread Robert S. Hansel
gards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Mon, 17 Jun 2024 15:28:13 -0500 From:Stuart Holland Subject: Re: RACF permissio

Re: RACF/DB2 Search Question?

2024-04-04 Thread Robert S. Hansel
. Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com Upcoming RSH RACF Training - WebEx

Re: RACF, external password management

2024-03-01 Thread Robert S. Hansel
your resource managers processing logons can handle special characters. Longer term solution is MFA. I recommend you contact the authors of this regulation and ask them to provide you with the list of common passwords they expect you to disallow. Regards, Bob Robert S. Hansel

Re: RACF, external password management

2024-02-29 Thread Robert S. Hansel
Hi Linda, How do you define "common password"? Regards, Bob Robert S. Hansel 2024 IBM Champion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Wed, 28 Feb 2024 15:3

ISVs - Statements of z/OS System Integrity

2024-02-03 Thread Robert S. Hansel
t and can you provide its URL? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -- For IBM-MAIN subscribe / signoff / archive a

Re: Racf Userid

2024-01-11 Thread Robert S. Hansel (RSH)
rmation, try adding the UAUDIT attribute to the ID to record all its access activity. This activity might provide some clues as to how and from where the ID is being used. If you have zSecure Access Monitor, it can also provide helpful access activity information. Regards, Bob Robert S. Hansel Lead

Re: zOSMF install - SDSF ISFPRMxx

2023-12-08 Thread Robert S. Hansel (RSH)
Hi Peter, You might also find my presentation on SDSF and RACF helpful, which I just posted on my website. https://www.rshconsulting.com/RSHpres/RSH_Consulting__SDSF_and_RACF__November_2023.pdf Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211

Re: RACROUTE REQUEST=AUTH problem

2023-11-30 Thread Robert S. Hansel (RSH)
ronment is running. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message- Date:Wed, 29 Nov 2023 16:18:49 + From:Rob Scott Subject: Re: RACROUTE REQUEST=AUTH problem Ye

Re: RACF ICH408I messages

2023-10-05 Thread Robert S. Hansel (RSH)
ring_&_Reporting__May_2019.pdf Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com Upcoming RSH RACF Training - WebEx - RAC

Re: XCFAS and TRUSTED

2023-08-21 Thread Robert S. Hansel (RSH)
PRIVILEGED or TRUSTED for any tasks but relented once I learned of this for the sake of system availability. I now warn clients whenever I discover any of these tasks running without TRUSTED. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in

Re: XCFAS and TRUSTED

2023-08-20 Thread Robert S. Hansel (RSH)
https://www.ibm.com/docs/en/zos/2.5.0?topic=management-requirements-participating-in-automatic-restart What healthcheck reported the issue? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.rshconsulting.com -Original Message-

Re: eliminate use of id(0)

2023-04-12 Thread Robert S. Hansel (RSH)
Hi Colin, What is the product? If you share this, perhaps someone who is familiar with the product and may have already addressed this issue can respond. Ask the vendor if access to FACILITY BPX or UNIXPRIV resources could be used in lieu of Superuser authority. Regards, Bob Robert S. Hansel

Re: RACF - SDSF question

2023-02-08 Thread Robert S. Hansel (RSH)
ULOG. ULOG will show you all the access checks SDSF is making along with the results of each of these checks. SECTRACE is a phenomenal diagnostic tool that we use often. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 30th Ann

Re: RACF - SDSF question

2023-02-08 Thread Robert S. Hansel (RSH)
Ed, What you suggest only applies to DATASET profiles. With General Resource profiles such as those for OPERCMDS, the profile is always Discrete if fully spelled out and Generic only if it has masking characters. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc

Re: rexx and IDCAMS functions

2022-08-17 Thread Robert S. Hansel (RSH)
Hi Lizette, What, if any, ICH408I messages do you see in SYSLOG. Do you have the necessary FACILITY STGADMIN profile permissions to perform these functions? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 30th Anniversary *** 617-969-8211

Re: Superuser (su) in batch

2022-08-12 Thread Robert S. Hansel (RSH)
//SYSINDD DUMMY //SYSTSPRT DD SYSOUT=* //SYSTSIN DD * PROF MSGID WTPMSG OSHELL echo id | su OSHELL print 'id' | su Regar

Re: SDSF & TSS (RACF)

2022-05-25 Thread Robert S. Hansel (RSH)
Hi Mark, The option prevents all the violations when you 's' select the entire job. It won't help when you select the job with ? and then select individual SYSOUTs. For the latter, it is WAD. Regards, Bob Robert S. Hansel35 years of RACF Experience Lead RACF

FW: SDSF & TSS (RACF)

2022-05-25 Thread Robert S. Hansel (RSH)
Mark, I'm surprised it didn't work. Did you code a CUSTOM(proplist) parameter in _all_ your GROUP statements that points to the PROPLIST NAME(proplist) statement with the PROPERTY parameter? And did you refresh the ISFPARMS in all the SDSF servers? Regards, Bob Robert

Re: SDSF & TSS (RACF)

2022-05-24 Thread Robert S. Hansel (RSH)
July 2008 issue of our RACF Tips newsletter. https://www.rshconsulting.com/racftips/RSH_Consulting__RACF_Tips__July_2008.pdf Regards, Bob Robert S. Hansel35 years of RACF Experience Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.t

Re: SAF without an ESM

2022-05-05 Thread Robert S. Hansel (RSH)
ccess authorization check. I've only come across one installation that had an exit to do just what you suggest. Regards, Bob Robert S. Hansel35 years of RACF Experience Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.co

Re: What is the audit basis to prevent read access to z/OS PARMLIB's?

2022-02-05 Thread Robert S. Hansel (RSH)
don't provide it, or at least monitor activity to discover who is checking you out. Why make it easy for someone to probe your system undetected. The STIG and the RACF SAG should both be amended to indicate the PARMLIB concatenation, not just SYS1.PARMLIB. Regards, Bob Robert S. Hansel

Re: Having some challenges with a SORT Utility

2022-01-20 Thread Robert S. Hansel (RSH)
report you are looking for without having to write a single line of code. I suggest you contact your RACF Admin team to ask them about the availability of an IRRDBU00 unload and zSecure. Regards, Bob Robert S. Hansel35 years of RACF Experience Lead RACF Specialist

Re: Change password

2022-01-13 Thread Robert S. Hansel (RSH)
Gadi, Use of the operand REVOKE(date) requires SPECIAL. It might work if the user executing the ALTUSER command is the owner of the user profile (e.g., ). Regards, Bob Robert S. Hansel35 years of RACF Experience Lead RACF Specialist 2021 #IBMChampion RSH

Re: LDAP confusion with security settings

2021-07-10 Thread Robert S. Hansel (RSH)
ograms? My extreme SWAG is that it is being used to handle password expiration and password changes. Regards, Bob Robert S. Hansel2021 #IBMChampion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshcons

Re: Unix Permissions Display Question

2021-07-03 Thread Robert S. Hansel (RSH)
, Bob Robert S. Hansel2021 #IBMChampion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsulting.com --- Upcoming RSH RACF Tra

Re: z14 HMC log information

2021-03-25 Thread Robert S. Hansel (RSH)
m/racftips/RSH_Consulting__RACF_Tips__January_2013.pdf Regards, Bob Robert S. Hansel2021 #IBMChampion Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshcons

Re: SMF Type65 - Determine who Deleted the Dataset

2021-01-01 Thread Robert S. Hansel (RSH)
Hi Jasi, You would most likely only see a RACF SMF DELRES event record for the deletion if the DATASET class is included in SETROPTS AUDIT set of classes. If DATASET is set for AUDIT, be sure your RACFRW command specifies EVENT ALLSVC. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH

Re: RACF and ICHDEX01 Exit

2020-08-11 Thread Robert S. Hansel (RSH)
sting masked passwords to DES using PWDCOPY. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsulting.com --- Upcoming RSH

Re: SMF record

2020-07-14 Thread Robert S. Hansel (RSH)
. If JESINPUT and JESJOBS are active, look at associated Access Monitor records as they may provide further details. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsultin

Re: Confirm or deny existence of old masking password?

2020-07-11 Thread Robert S. Hansel (RSH)
it without a password. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsulting.com --- Upcoming RSH RACF Training - WebEx

Re: JESSPOOL

2020-03-13 Thread Robert S. Hansel (RSH)
ete output. Then, assuming they specified ON, have the user execute the ULOG command to see the RACF calls and their results. This assumes the user has authority to use ULOG - SDSF class resource ISFCMD.ODSP.ULOG.jesname or the ISFPARMS equivalent. Regards, Bob Robert S. Hansel Lead RACF Spec

Re: Restrict users to Purge Jobs in TSO

2020-02-19 Thread Robert S. Hansel (RSH)
SOLE ** UACC(READ) <- Optionally add AUDIT(ALL) for future remediation SETROPTS CLASSACT(CONSOLE) SETROPTS RACLIST(CONSOLE) <- Optional, but recommended for performance Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/ro

Re: Rexx or similar to clone a RACF user?

2020-01-28 Thread Robert S. Hansel (RSH)
Ituriel, Very clever. However, I recommend using the 0203 record for group connections instead of the 0102 record. If the user is connected to a UNIVERSAL group, there won't be a 0102 record unless the user has an authority greater than USE. Regards, Bob Robert S. Hansel Lead RACF Speci

Re: RACEOUTE REQUEST=RESUME ?

2019-12-18 Thread Robert S. Hansel (RSH)
Paul, Is there a reason this has to be done in Assembler? Using TSO batch, you could simply execute command:ALTUSER userid RESUME Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF

Re: Tracing RACF?

2019-10-02 Thread Robert S. Hansel (RSH)
Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsulting.com -Original Message- Date:Tue, 1 Oct 2019 11:10:21 +0100 From:Sean Gleann Subject: Re: Tracing RACF? Joao: yes, I

Re: Tracing RACF?

2019-09-26 Thread Robert S. Hansel (RSH)
to match the access granted by corresponding GAT entries. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsulting.com -Original Message- Date:Wed, 25 Sep 2019 14:33:40 + From

RSH Consulting - RACF Survey - June 2019 - Performance - ERV

2019-07-21 Thread Robert S. Hansel (RSH)
f our survey have been posted to our website. Go to the "RACF Center" webpage, click on "RSH RACF Surveys", and then click on the survey link itself. Many thanks to the 39 individuals who participated. www.rshconsulting.com Regards, Bob Robert S. Hansel Lead RACF Specialist RSH

Re: Can backup mechanisms be used to steal RACF database? was Re: mainframe hacking "success stories"?

2019-05-14 Thread Robert S. Hansel (RSH)
Clark, The answer to your original question is 'yes'. With regard to FDR, see the following article in our RACF Tips newsletter. https://www.rshconsulting.com/racftips/RSH_Consulting__RACF_Tips__January_2008.pdf Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, In

Re: Dancing around RMM

2018-12-21 Thread Robert S. Hansel (RSH)
Skip, Rather than trying to read the tapes, since you are discarding them, use EDGINERS to erase them. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel www.twitter.com/RSH_RACF www.rshconsulting.com -Original Message

Re: Strange JES2 SPOOL Offload issue

2018-09-14 Thread Robert S. Hansel (RSH)
Todd, In RACF, if the WRITER class is active, is the UACC set to READ for the profile protecting resource jesname.LOCAL.OFF2.ST, where 'jesname' is the name of your JES subsystem? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linke

Re: Yet Another Mainframe z10 Bites the Dust!

2018-09-14 Thread Robert S. Hansel (RSH)
Todd, Unfortunately, ERASE only works on DASD datasets. It doesn't do tapes, even virtual ones. Clever idea nonetheless. George, Does your tape management product or VTL hardware vendor provide utilities for this task? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting

Re: Filemanager and security

2018-04-17 Thread Robert S. Hansel (RSH)
Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel https://twitter.com/RSH_RACF www.rshconsulting.com -Original Message- Date:Mon, 16 Apr 2018 18:22:32 + From:"Pommier

Re: Filemanager and security

2018-04-13 Thread Robert S. Hansel (RSH)
x27;s equivalent? If it does, have you tried the function with an ID that does not have this access? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel https://twitter.com/RSH

Re: Problem with dataset authorization

2018-03-16 Thread Robert S. Hansel (RSH)
If you are new to RACF some changes require the "in memory" copy to be refreshed before the change takes effect. On Thu, Mar 15, 2018 at 6:05 AM, Robert S. Hansel (RSH) < r.han...@rshconsulting.com> wrote: > Hi Ron, > > Here are a couple of thoughts. > > When you c

Re: Problem with dataset authorization

2018-03-15 Thread Robert S. Hansel (RSH)
erent RACF database than the one where you created the profile? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel https://twitter.com/RSH_RACF www.rshcons

Re: Health Check JES_NJE_SECURITY

2018-03-02 Thread Robert S. Hansel (RSH)
recommend you define &RACLNDE in each of your RACF databases and in each such profile include only the nodes for the systems sharing that particular database. Do so even on standalone systems or Multi-Access Spool configurations. This will facilitate spool reloads. Regards, Bob Robert S. Ha

Re: How to find what performed an OMVS unmount?

2017-12-29 Thread Robert S. Hansel (RSH)
udit class FSOBJ. Use caution in auditing Unix events because of the potential high volume of SMF records. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_

Re: How to find what performed an OMVS unmount?

2017-12-28 Thread Robert S. Hansel (RSH)
ges do not exclude 80 records, you are correct that they are being collected. Also look for SUBSYS settings that might be excluding them for certain subsystems. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 61

Re: How to find what performed an OMVS unmount?

2017-12-22 Thread Robert S. Hansel (RSH)
, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsulting.com -Original Message- Date:Tue, 19 Dec 2017 18:10:10 -0600 From:Peter Ten

Re: IBM-MAIN Digest - 18 Dec 2017 to 19 Dec 2017 (#2017-353)

2017-12-21 Thread Robert S. Hansel (RSH)
Peter, If this is a RACF protected system and depending on what audit settings were in effect, you might see an SMF 80 record for the unmount. The event code is 55. If you have SMF unload records available, look for event UMNTFSYS. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH

Re: DFSORT: RACFICE query - how to extract all commands containing some text value

2017-12-14 Thread Robert S. Hansel (RSH)
it on our "RACF Center" webpage along with other useful RACF information. http://www.rshconsulting.com/racfres.htm Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel http://

Re: Finding OMVS Files with Owner IDs for Deleted Owners?

2017-12-03 Thread Robert S. Hansel (RSH)
or IRRHFSU for the entire file system with a USERID having the UAUDIT attribute. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rs

Re: Batch TSO command (ADDUSER) tracing and diagnostics

2017-10-27 Thread Robert S. Hansel (RSH)
using to create IDs? What if any segments is it creating along with the ID? There may be other pre-command checks we can recommend. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. *** Celebrating our 25th Year *** 617-969-8211 www.linkedin.com/in/roberthansel

Re: RACF Database

2017-05-25 Thread Robert S. Hansel (RSH)
le or you want to exclude groups or users from a Group-SPECIAL administrator's scope-of-groups. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.co

Re: RACF Database

2017-05-24 Thread Robert S. Hansel (RSH)
Hi Skip, Point of clarification. IRRDBU00 no longer required UPDATE access with NOLOCKINPUT as of z/OS 2.2. Regards, Bob -Original Message- From: Robert S. Hansel (RSH) [mailto:r.han...@rshconsulting.com] Sent: Wednesday, May 24, 2017 6:07 AM To: 'IBM Mainframe Discussion

Re: RACF Database

2017-05-24 Thread Robert S. Hansel (RSH)
the database, and BLKUPD to repair the database. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsulting.com -Original Message

Re: RACF Database (was: Sample JCL for file transfer using NJE/TCPIP)

2017-05-24 Thread Robert S. Hansel (RSH)
ompress on any dataset. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsulting.com -Original Message- Date:Tue, 23 May

Re: RACF Database (was: Sample JCL for file transfer using NJE/TCPIP)

2017-05-22 Thread Robert S. Hansel (RSH)
st have exactly the same UNIT, SPACE, and DCB characteristics as the source database, including CONTIG. The copy needn't be PSU unless you plan to RVARY SWITCH to it so that it becomes live. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Speci

Issue with SK4T-4949-13 - IBM Online Library: z/OS V2R2 Collection, March 2017

2017-04-26 Thread Robert S. Hansel (RSH)
inconvenient. I'm hoping the IBMers monitoring this list will take note and have this rectified. I complained through the website, but got no response. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, Inc. 617-969

Re: Erase on Scratch

2017-04-22 Thread Robert S. Hansel (RSH)
n the performance of ERASE in z/OS 2.1 and 2.2. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsultin

Re: RACF TEMPDSN improvement with the zOS 1.13

2017-04-19 Thread Robert S. Hansel (RSH)
following scenario: 1. The job or user allocates a temporary data set. 2. You activate the TEMPDSN class. 3. The job or user opens the data set. 4. Because activating the TEMPDSN class restricts the authority to open a temporary data set, the user or job receives an abend. (end-quote) Regards, Bob

Re: RACF Non-expiring passwords

2017-03-21 Thread Robert S. Hansel (RSH)
nd verify it is the correct source for these logons. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rs

Re: Problem Generating CA-7 SASSBSTR Batch LJOB Output

2017-03-09 Thread Robert S. Hansel (RSH)
y BTI reads your BATCHO#n (which is empty) and writes it contents to SYSPRINT. Jeffrey Holst On Tue, 7 Mar 2017 14:14:37 -0500, Robert S. Hansel (RSH) wrote: >Greetings all, > >I was able to get SASSBSTR running successfully, but in the process may have >discovered a bug in the pr

Re: Problem Generating CA-7 SASSBSTR Batch LJOB Output

2017-03-07 Thread Robert S. Hansel (RSH)
use the ones in CA7's configuration, I get output as expected. Yet, the job runs successfully with RC=0 in both cases, and there are no error messages of any sort. Thank you to all who offered suggestions and advice. Regards, Bob Robert S. Hansel *** Celebrating 30 years workin

Problem Generating CA-7 SASSBSTR Batch LJOB Output

2017-03-03 Thread Robert S. Hansel (RSH)
, the output from the LJOB command. I've searched the manuals and cannot figure out how to the get the output I desire and was hoping someone could be of assistance. TIA. Regards, Bob Robert S. Hansel *** Celebrating 30 years working with RACF *** Lead RACF Specialist RSH Consulting, In

Re: ICHPWX01 sample problem

2016-09-02 Thread Robert S. Hansel (RSH)
Hi Ed, If you are curious as to what RACF exits installations are using, see our survey of a few years ago. (Beware of line wrap.) http://www.rshconsulting.com/surveys/RSH_Consulting__RACF_Survey_013__Exits.pdf Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969

Re: Privileged Users (was: EXTERNAL: Re: [EXTERNAL] Re: smp/e sha-2 support?)

2016-05-18 Thread Robert S. Hansel (RSH)
because it allows a user to look at all profiles and SETROPTS options without changing any audit settings. Just curious, in your 'elevated access' report, do you include users with UID 0 or access to BPX.SUPERUSER? Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, In

Re: OA49446 on RSU1603 - RACF / DFSMS change

2016-04-29 Thread Robert S. Hansel (RSH)
the related dataset. This is going to make protecting sensitive datasets more complicated. I wonder if IBM's Health Check for APF library protection will now include aliases as well. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211

Re: List user's

2016-04-16 Thread Robert S. Hansel (RSH)
to a SIEM product, you may be able to use its capabilities to generate your report. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshcons

Re: How to log or trace BCPII activity on the SE?

2016-03-19 Thread Robert S. Hansel (RSH)
Hi Thomas, Is the FACILITY class RACLISTed on the system where you are having the problem? Look for it in the section titled "SETR RACLIST CLASSES" in the output from a RACF "SETROPTS LIST" command. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consultin

Re: Outsourcing Stories Good or Bad!

2016-02-26 Thread Robert S. Hansel (RSH)
Hi Mark, See the article "Outsource Risk" in the October 2014 edition of our RACF Tips newsletter. http://www.rshconsulting.com/racftips/RSH_Consulting__RACF_Tips__October_2014.pdf Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linke

Re: [Bulk] Re: [Bulk] UADS (was Re: [Bulk] Re: COBOL v5)

2016-02-17 Thread Robert S. Hansel (RSH)
aking backups or copies of a live RACF database. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsulting.com -Original Message- Date:Tue, 16 Feb 2016 21:48:37 +0100 From:

Re: [Bulk] Re: [Bulk] UADS (was Re: [Bulk] Re: COBOL v5)

2016-02-15 Thread Robert S. Hansel (RSH)
"RACF Database Backup" can be found on the RACF Center webpage of our website at the following URL. For those unfamiliar with our website, you'll find lots of other useful RACF information there as well. http://www.rshconsulting.com/racfres.htm Regards, Bob Robert S. Hansel Lead

Re: RACF reporting tool

2015-07-15 Thread Robert S. Hansel (RSH)
Sharon, In addition to the products others have mentioned, also consider EKC's products - www.ekcinc.com Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsultin

Re: OMVS segments created on demand

2015-06-06 Thread Robert S. Hansel (RSH)
ew its JESINTERFACELEVEL configuration parameter and related RACF controls. See our RSH RACF Tips article on this topic: http://www.rshconsulting.com/racftips/RSH_Consulting__RACF_Tips__April_2010.pdf Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin

Re: A Total Eclipse of the Spool

2015-04-18 Thread Robert S. Hansel (RSH)
Hi Ed, If you will be using the FTP JES interface, I suggest you review our RACF Tips newsletter article on this topic. http://www.rshconsulting.com/racftips/RSH_Consulting__RACF_Tips__April_2010.pdf Regards, Bob -Original Message- Date:Fri, 17 Apr 2015 01:34:16 -0400 From:Rob

Re: APF-authorized calling non-authorized

2015-03-16 Thread Robert S. Hansel (RSH)
is circa 1984. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshconsulting.com --- 2014-2015 RACF Training - Audit

Re: Has Anyone Seen this in ISPF before?

2014-10-30 Thread Robert S. Hansel (RSH)
content of the profiles. My advice to the OP would be to delete the TSO segment and recreate it just in case there are other problems with the information stored in RACF for this user. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in

Re: Handle RACF abend in LE C

2014-05-11 Thread Robert S. Hansel (RSH)
I messages. You'll either need to define the programs with their associated libraries to RACF or, unless you are specifically trying to create a daemon that needs BPX.SERVER authority, remove your access to the latter. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, In

Re: OMVS UID display

2013-12-15 Thread Robert S. Hansel (RSH)
which your USERID is in the access list? Execute RLIST UNIXMAP U12345 ALL to check. Regards, Bob Robert S. Hansel Lead RACF Specialist RSH Consulting, Inc. 617-969-8211 www.linkedin.com/in/roberthansel http://twitter.com/RSH_RACF www.rshcons

  1   2   >