IBM Support

PM24862: UNABLE TO PURGE A USER IN THE AUTHCACHE.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Describe purgeUserInAuthCache mbean function and details.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server V7.0                                 *
    ****************************************************************
    * PROBLEM DESCRIPTION: After adding a user to a group in       *
    *                      RACF that is authorized to a certain    *
    *                      role, the user is still not             *
    *                      authorized. A restart of the server     *
    *                      is required for the changes to take     *
    *                      effect immediately.                     *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    The group membership information for a RACF user is stored
    inside the RACO (RACF Object). The zWAS native security code
    holds a cache of RACOs until the user is purged from the
    PlatformCredential cache in java. The PlatformCredential cache
    in java is not linked to the AuthCache in any way, so purging
    a user from the auth cache has no effect on the
    PlatformCredential cache, so the old RACO is still being used
    for the authorization decision.
    

Problem conclusion

  • WebSphere Application Server has been modified to also purge
    the user from the PlatformCredential cache, which will in turn
    call security code to delete the RACO.
    
    APAR PM24862 is currently targeted for inclusion in Service
    Level (Fix Pack) 7.0.0.15 of WebSphere Application Server V7.0.
    
    Please refer to URL:
    //www.ibm.com/support/docview.wss?rs=404&uid=swg27006970
    for Fix Pack availability.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM24862

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2010-10-20

  • Closed date

    2011-01-04

  • Last modified date

    2011-04-04

  • APAR is sysrouted FROM one or more of the following:

    PM24668

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

  • R700 PSY UK65061

       UP11/03/04 P F103

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
10 February 2022