Previous Topic: Authorizations for Command Processing

Next Topic: SURROGAT Authorization (CA VM:Secure only)

DIAGPCHK Authorization (CA VM:Secure only)

DIAGPCHK authorization controls the use of DIAGNOSE X‘A0’ subfunction X‘04’ and subfunction X‘0C’. Use of DIAGNOSE X‘A0’ and this authorization are valid only if you are using the CA VM:Secure Rules Facility. DIAGNOSE X‘A0’ with subfunction X‘04’ lets a user ask CA VM:Secure to verify a user’s logon password in the object directory. DIAGNOSE X‘A0’ with subfunction X‘0C’ lets a user verify that a user ID is allowed to perform a LOGON BY of another user ID. You often use DIAGPCHK in conjunction with SURROGAT authorization.

If CA VM:Secure is not available and you still want a user ID with DIAGPCHK authorization that is able to verify passwords, place an IUCV DUALPASS statement in the directory entry of the user ID specified in the GRANT DIAGPCHK authorization.

Example:

To use DIAGNOSE X’A0’ subfunction 4 in CADAM CADRIVL (CADAMSVM) and use CA VM:Secure to verify passwords, use the following GRANT record:

GRANT DIAGPCHK TO CADAMSVM