|
Results |
|
Intermittent ‘Passticket generation failed’ messages
|
|
PassTicket TCP/IP connection impersonation functioning incorrectly for 8 byte userids
|
|
Additional RACF Passticket setup
Create a profile in the PTKTDATA class by entering: RDEFINE PTKTDATA SERNET SSIGNON(user_must_choose) APPLDATA(’NO REPLAY PROTECTION’)
|
|
|
Remove SERSET execution from Sernet start-up for ChangeMan SSM
A customer runs both ChangeMan ZMF and ChangeMan SSM on several LPARs. If, after an IPL, SSM starts before ZMF an invalid version of ZMF PassTicket PC routine SERXPTIK can be loaded into CSA. This prevents users from connecting to ZMF using the TCP/IP connection method until such time as the correct version of SERXPTIK is loaded into CSA.
|
|
|
ACF2 Administration to define PassTicket
SET PROFILE(PTKTDATA) DIVISION(SSIGNON) Insert the SERNET PTKTDATA data by entering: INSERT SERNET SSKEY(user_must_choose
|
|
|
SSM Started Task gets error SER0603E TCP/IP logons will not be allowed due to an error in passticket initialization
Passtick Initialization was introduced in Changeman ZMF 8.1, but is not part of ChangeMan SSM. However, both products do use SERNET , which is issuing this message. If your site has multiple mainframe Microfocus products ,(formerly SERENA), that use the SERCOMC.LOAD library, then the recommendation is to use a STEPLIB to avoid compatibility issues that can be introduced with different versions of the SERCOMC.LOAD library.
|
|
|
CA Top Secret Administration to define PassTicket to ZMF 8.1
TSS ADDTO(RDT) RESCLASS(PTKTDATA) ACLST(ALL,READ,UPDATE) MAXLEN(26) Assign ownership of SERNET TSS ADDTO(owner name) APPLICATION(SERNET)
|
|
|
PassTicket generation problems – a guide to self-diagnosis in a RACF environment
//SYSTSIN DD * RLIST PTKTDATA SERNET SETROPTS LIST
|
|
|
ZMF 8.1 Passticket validation for protected userids
1. The primary userid, SERE in this example, MUST be authorized to impersonate userids for this ZMF subsystem. This can be achieved by adding the userid to the ACF2BAT table in SERLCSEC or by granting READ access to the SAFCLASS/SAFRSRCE profile specified in the same module (default FACILITY/SERENA. SERNET .AUTHUSR), if it was not already. Further information can be found here:
|
|
|
Sernet Connect Compare Function
Sernet Connect Compare Function
|
|
|