IBM Support

PI40828: CICS ENF NOTIFY RECEIVED FROM RACF BUT A TASK ISSUING EXEC CICS SIGNOFF+SIGNON REUSES OLD USUD.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Customer is protecting CICS resources (programs) with RESSEC=ON
    and MCICSPPT class (XPPT=CICSPPT).
    When a specific RACF commands is sent and it is affecting the
    group authorization of a user, the ENF is received by CICS.
    A CICS dump shows that USUD has the following flags on
    USUD_NOTIFY_RECEIVED and USUD_DELETE_IMMEDIATE .
    But the application program is issuing
    EXEC CICS SIGNOFF and EXEC CICS SIGNON in the same task and
    task continues without refreshing the USUD based on the
    ENF just received.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All                                          *
    ****************************************************************
    * PROBLEM DESCRIPTION: In a transaction an EXEC CICS SIGNOFF   *
    *                      command is run followed by an EXEC CICS *
    *                      SIGNON command for the same USERID.     *
    *                      The same USUD token is used by signon   *
    *                      as was used before signoff.             *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    A transaction runs an EXEC CICS SIGNOFF command followed by an
    EXEC CICS SIGNON command for the same USERID.  The signon reuses
    the USUD token that was being used before signoff, no new USUD
    token is created and the user's security attributes are not
    reestablished.
    
    If a user's RACF profile has changed, running EXEC CICS SIGNOFF
    followed by an EXEC CICS SIGNON for the same USERID in a single
    transaction will not create a new USUD token to reestablish the
    user's security attributes.
    
    Subsequent transactions will use the old USUD token with the
    user's old security attributes.
    

Problem conclusion

  • DFHUSAD has been changed so that a new USUD token is created
    when EXEC CICS SIGNOFF followed by EXEC CICS SIGNON are run
    in a single transaction for the same USERID.
    

Temporary fix

  • FIX AVAILABLE BY PTF ONLY
    

Comments

  • ×**** PE17/08/14 FIX IN ERROR. SEE APAR PI85903  FOR DESCRIPTION
    

APAR Information

  • APAR number

    PI40828

  • Reported component name

    CICS TS Z/OS V5

  • Reported component ID

    5655Y0400

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2015-05-11

  • Closed date

    2015-06-22

  • Last modified date

    2017-11-17

  • APAR is sysrouted FROM one or more of the following:

    PI31402

  • APAR is sysrouted TO one or more of the following:

    UI28782 UI28783

Modules/Macros

  • DFHUSAD
    

Fix information

  • Fixed component name

    CICS TS Z/OS V5

  • Fixed component ID

    5655Y0400

Applicable component levels

  • R800 PSY UI28782

       UP15/07/02 P F507

  • R900 PSY UI28783

       UP15/07/02 P F507

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.1","Edition":"","Line of Business":{"code":"LOB35","label":"Mainframe SW"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.1","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
17 November 2017