Ensure that authorizations are correct for callers of WLM services

Description

With z/OS® V2R2, the minimum authorization requirements for the callers of following Workload Management services are changed:
  • IWMDEXTR – Extract WLM service definition
  • IWMDINST – Install a service definition
  • IWMPACT – Activate service policy.

Resource MVSADMIN.WLM.POLICY in the FACILITY class is mandatory. Callers of IWMDEXTR must have READ access and callers of IWMDINST and IWMPACT must have UPDATE authority. Appropriate access authorities are also required when using the WLM ISPF Application to install or extract a service definition or activate a service policy.

In previous releases, MVSADMIN.WLM.POLICY was optional. If you did not define this resource (or a generic one), any user could invoke IWMDEXTR, IWMDINST, and IWMPACT.

Table 1 provides more details about this migration action. Use this information to plan your changes to the system.

Table 1. Information about this migration action
Element or feature: BCP.
When change was introduced: z/OS V2R2.
Applies to migration from: z/OS V2R1 and z/OS V1R13.
Timing: Before the first IPL of z/OS V2R2.
Is the migration action required? Yes, if the resource MVSADMIN.WLM.POLICY in the FACILITY class is not already defined.
Target system hardware requirements: None.
Target system software requirements: None.
Other system (coexistence or fallback) requirements: None.
Restrictions: None.
System impacts: None.
Related IBM® Health Checker for z/OS check: None.

Steps to take

Define resource MVSADMIN.WLM.POLICY in the FACILITY class. Then, provide read access or update authority to users according to their needs.

Reference information