Previous Topic: Commands and Functions that Generate External Security Events

Troubleshooting External Security

This section contains the following topics:

CA Top Secret Options that Affect Product Access Requests

CA Top Secret Options that Affect Product Access Requests

CA Top Secret has many possible configurations and combinations. Some of the configurations affect the CA OPS/MVS requests for access authorization. Review the following troubleshooting topics.

Access Granted Without Reference to Access Profiles

Symptom:

My CA Top Secret batch job allows access requests to CA OPS/MVS resources without reference to the CA Top Secret defined resource access profiles.

Solution:

Setting the batch mode of CA Top Secret to DORM or WARN can affect CA OPS/MVS commands or functions the z/OS batch jobs issue.

Change the value of MODE for the user to IMPL or FAIL.

ACID Bypassed Security Checking

Symptom:

My CA Top Secret ACIDs allow access requests to CA OPS/MVS resources without reference to the CA Top Secret defined resource access profiles.

Solution:

Verify that the NORESCHK attribute is not attached to the individual ACIDs.

TSS REMOVE(acid) NORESCHK
NORESCHK

Lets an ACID bypass security checking for all owned resources except data sets and volumes.