Skip to Main Content
IBM Z Software


This portal is to open public enhancement requests against IBM Z Software products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Workspace zSecure
Categories zSecure Admin
Created by Guest
Created on Mar 26, 2024

Enhancements to Access Monitor Option 3 and Option 8

When using Option 3 or Option 8 to perform inactive permission reporting we are suggesting the following enhancements to Access Monitor.

  • Access Monitor AM.8.1, AM.8.2, and AM.8.3 all produce commands to cleanup profiles, permissions, or connections. Using AM.8.2 as an example you get commands created to delete inactive permissions and commands to restore those permissions. However, what is missing is a report of what is being proposed to being deleted. A possible solution is to use the reporting from AM.3 and select permissions with a zero count. However, the number of PERMIT delete commands generated with AM.8.2 does not agree with the output from the report in AM.3.

When you have an environment of multiple RACF DB’s that are kept insync via RRSF you need to analyze inactivity across the environment. So, you need to use as input the Access Monitor data from all the systems in the environment, all the CKFREEZE files, and Access Monitor requires a RACF DB or Unload from each system in the Access Monitor data.

  • The AM.8 options do not handle environments with multiple RACF DB’s. The ISPF screens limit you to one RACF DB/Unload as an input file, but you can select multiple AM Data files / CKFREEZE files. But this results in a CKR0617 message because you do not have a RACF DB/UNLOAD from those systems.

  • To bypass the limitation of AM.8 of one RACF DB/UNLOAD, we tried accessing the RACF Primary or Backup via the zSecure Server in hopes it would see it as a single instance. The AM.8 Options do not allow usage of a RACF Db as an input source if the ALLOC statement uses ZSECNODE. You get a CKR3005 message. I would assume this restriction is removed in version 3.1 since it is our understanding that you can read Access Monitor data over the zSecure Server.

  • The AM.3 option does allow for inputs from all the impacted systems however when you specify zero counts, a permission is written to the report if the permission has a zero on Successes, Violations or Unknowns. And if its zero on at least one of the RACF DB’s. This would mean if you intended to keep your RACF DB’s in sync, any inactivity on any single RACF DB could cause the permission to be deleted. The permission needs to show a zero count on all systems.

  • We have also noticed that the run time for a job running AM.3 versus AM.82, the AM8.2 jobs run significantly longer and both are reading in the same input files. It appears it has to do with what is pre-selected.

Idea priority Medium
1 MERGED

Enhancements to Access Monitor Option 8 when dealing with multiple RACF systems

Merged
Suggesting the following enhancements to AM.8.1, AM.8.2, and AM.8.3: These three options all develop RACF Commands to delete the inactive object and to restore it if needed. But it would be good to provide a "report" of what is being proposed to b...
over 1 year ago in zSecure / zSecure Admin 1 Future consideration