z/OS Security Server RACF System Programmer's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Allowing access when RACF is inactive

z/OS Security Server RACF System Programmer's Guide
SA23-2287-00

When RACF® is inactive, any attempt to access a protected resource is passed to the RACROUTE REQUEST=AUTH preprocessing exit. The exit can determine whether to allow the access to proceed. If, for example, you want to allow one or more specific users to perform recovery operations, the exit must select those users. (If RACF is inactive, the normal privileges of OPERATIONS cannot be used because the RACF database might not be available to verify that a user is so authorized.) You should consider whether user IDs or batch job names that are authorized by the exits when RACF is inactive should also be allowed to use the system if RACF is running normally.

If the RACROUTE REQUEST=AUTH preprocessing exit routine grants or denies access to the data set, RACF failsoft processing can prompt the operator.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014