z/OS Security Server RACF Messages and Codes
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


IRRH507I

z/OS Security Server RACF Messages and Codes
SA23-2291-00

IRRH507I
RACF cannot assign unique UNIX IDs when users or groups that do not have OMVS segments use certain z/OS UNIX services. One or more requirements are not satisfied.

Explanation

The RACF® UNIX identity migration check has determined that you want RACF to assign unique UNIX IDs when users or groups without OMVS segments use certain z/OS® UNIX services. However, RACF is not able to do this because one or more requirements are not satisfied.

No migration actions are required because enabling RACF to automatically assign unique z/OS UNIX identities is the recommended alternative to assigning unique UNIX UIDs and unique GIDs to users and groups in advance of their need to access z/OS UNIX functions. However, if you want to use this support, you should examine the list of requirements and ensure that they are satisfied:
  1. The RACF database is enabled for application identity mapping (AIM) stage 3.
  2. The UNIXPRIV class profile SHARED.IDS is defined and the UNIXPRIV class is active and RACLISTed.
  3. The FACILITY class profile BPX.NEXT.USER is defined and its APPLDATA field has valid ID values or ranges.
  4. The FACILITY class profile BPX.UNIQUE.USER is defined.

See z/OS Security Server RACF Security Administrator's Guide or more information about enabling RACF for automatic assignment of unique UNIX identities.

The check produces a report listing the requirements. An "E" in the "S" (Status) column indicates that a requirement is not satisfied. For example, if the RACF database has not been enabled for AIM stage 3, this requirement is flagged as an exception. If the "S" field is blank, the requirement is satisfied. One or more requirements are not satisfied and have been flagged as an exception in the Status column.

System action

The check continues processing. There is no effect on the system.

Operator response

Report this problem to the system security administrator.

System programmer response

None.

Problem determination

None.

Source

Module

IRRHCR10

Routing code

N/A

Descriptor code

N/A

Automation

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014