CA ACF CA RS 1711 Service List

Similar documents
CA ACF CA RS 1709 Service List

CA ACF CA RS 1610 Service List

CA ACF CA RS 1605 Service List

CA ACF CA RS 1705 Service List

CA ACF CA RS 1708 Service List

CA ACF CA RS 1409 Service List

CA Top Secret Security for z/os CA RS 1706 Service List

CA ACF CA RS 1602 Service List

CA ACF CA RS 1704 Service List

CA Mainframe Advanced Authentication CA RS 1702 Service List

CA ACF CA RS 1310 Service List

CA ACF CA RS 1512 Service List

CA ACF CA RS 1504 Service List

CA ACF CA RS 1412 Service List

CA Top Secret Security for z/os CA RS 1708 Service List

CA ACF CA RS 1406 Service List

CA Top Secret Security for z/os CA RS 1509 Service List

CA ACF CA RS 1501 Service List

CA ACF CA RS 1604 Service List

CA Top Secret Security for z/os CA RS 1710 Service List

CA ACF CA RS 1510 Service List

CA TLMS Tape Management CA RS 1709 Service List

CA Top Secret Security for z/os CA RS 1704 Service List

CA Top Secret Security for z/os CA RS 1803 Service List

CA ACF CA RS 1306 Service List

CA Top Secret Security for z/os CA RS 1310 Service List

CA Top Secret Security for z/os CA RS 1607 Service List

CA Top Secret Security for z/os CA RS 1412 Service List

CA Top Secret Security for z/os CA RS 1409 Service List

CA Top Secret Security for z/os CA RS 1404 Service List

CA Cleanup for ACF CA RS 1610 Service List

CA InterTest Batch CA RS 1408 Service List

CA ACF CA RS 1201 Service List

CA Common Services CA RS 1704 Service List

CA ACF CA RS 1404 Service List

CA LDAP CA RS 1701 Service List

CA Common Services CA RS 1702 Service List

CA OPS/MVS for JES CA RS 1704 Service List

CA 1 Tape Management CA RS 1403 Service List

CA OPS/MVS for JES CA RS 1511 Service List

CA OPS/MVS for JES CA RS 1805 Service List

CA JCLCheck Workload Automation CA RS 1403 Service List

CA Disk Backup and Restore CA RS 1801 Service List

CA PDSMAN PDS Library Management CA RS 1309 Service List

CA IMS Tools 18.0 / Chorus 4.0 for IMS Tools 1 CA RS 1703 Service List

CA Optimizer/II CA RS 1510 Service List

CA InterTest Batch CA RS 1510 Service List

CA LDAP CA RS 1406 Service List

CA InterTest/SymDump Batch/CICS CA RS 1710 Service List

CA OPS/MVS for JES **INCREMENTAL** 1 CA RS 1807 Service List

CA JCLCheck Workload Automation CA RS 1404 Service List

CA Endevor SCM 18.0 **Incremental INC00** 1 CA RS 1701 Service List

CA Top Secret Security for z/os CA RS 1403 Service List

CA NetMaster CA RS 1606 Service List

CA InterTest Batch CA RS 1510 Service List

CA Vantage Storage Resource Manager CA RS 1509 Service List

CA TLMS Tape Management CA RS 1404 Service List

Compliance Event Manager CA RS 1710 Service List

CA JCLCheck Workload Automation CA RS 1411 Service List

CA Mainframe Application Tuner CA RS 1511 Service List

CA NetMaster CA RS 1609 Service List

CA JCLCheck Workload Automation CA RS 1605 Service List

CA 1 Tape Management CA RS 1404 Service List

CA TPX Session Management CA RS 1511 Service List

CA JCLCheck Workload Automation CA RS 1408 Service List

CA Common Services CA RS 1408 Service List

CA Common Services CA RS 1604 Service List

CA JCLCheck Workload Automation CA RS 1407 Service List

CA Workload Automation ESP Edition CA RS 1501 Service List

CA Common Services CA RS 1504 Service List

CA JCLCheck Workload Automation CA RS 1610 Service List

CA SYSVIEW Performance Management CA RS 1702 Service List

CA OPS/MVS for JES **INCREMENTAL** 1 CA RS 1711 Service List

CA DB2 Tools 20.0 **INCREMENTAL** 1 CA RS 1706 Service List

CA Ideal for Datacom CA RS 1407 Service List

CA 1 Tape Management CA RS 1701 Service List

CA Common Services CA RS 1701 Service List

CA IMS Tools 18.0 / Chorus 4.0 for IMS Tools 1 CA RS 1511 Service List

CA Mainframe Application Tuner CA RS 1410 Service List

CA NetMaster CA RS 1711 Service List

CA JCLCheck Workload Automation CA RS 1412 Service List

CA 1 Tape Management CA RS 1510 Service List

CA JCLCheck Workload Automation CA RS 1705 Service List

CA View CA RS 1312 Service List

CA LDAP CA RS 1601 Service List

CA XCOM Data Transport for z/os CA RS 1509 Service List

CA Datacom/DB CA RS 1704 Service List

CA SymDump Batch CA RS 1408 Service List

CA Datacom/AD CA RS 1704 Service List

CA Jobtrac Job Management CA RS 1609 Service List

CA InterTest Batch CA RS 1404 Service List

CA Easytrieve Report Generator CA RS 1408 Service List

CA NetMaster 12.2 **Incremental INC01** 1 CA RS 1701 Service List

CA OPS/MVS WebCenter CA RS 1408 Service List

CA Web Administrator for ACF2 and TSS CA RS 1702 Service List

CA Endevor Software Change Manager CA RS 1402 Service List

CA Datacom/DB CA RS 1602 Service List

CA NetMaster CA RS 1602 Service List

CA View/Deliver/DRAS 14.0 **INCREMENTAL** 1 CA RS 1712 Service List

CA Easytrieve Report Generator CA RS 1610 Service List

Transcription:

CA ACF2 16.0 1 CA RS 1711 List Description Type RO93852 ACF2/IMS SUPPORT FOR IMS R15 PTF RO93853 ACF2/IMS SUPPORT FOR IMS R15 PTF RO97779 CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD PTF RO97780 CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD PTF RO97781 PROVIDE NEW FLAG IN LOGONID TO ONLY LOG MAINT ACCESSES PTF RO97810 215 USER RECORD SHOWS DATA FROM PRIOR LOGONID PTF RO97842 FAILED PROFILE CHANGE GETS RC 0 PTF RO97857 SAFHFACF CREATING INVALID RULES WHEN PATHS GREATER THAN 255 PTF RO97896 ACF70042 DURING COMPILE WITH RO96906 AND COMPDYN WITH WHEN ** PRP ** RO97911 PSCBUSER HAS >7BYTES AFTER RO96905 ON A PRE Z/OS 2.3 SYSTEM PTF RO97921 VALIDATE NON-APF MUSASS ADDRESS SPACE USE OF SUPERCALL PTF RO97933 JES2 EXIT4 AND EXIT54 OUT-OF-SYNCH AFTER RO93512 ** PRP ** RO98008 FIX ACFGINTP PLIST TO INDICATE EXPANDED AND INCLUDE LENGTH ** PRP ** RO98081 PKI SERVICES - 8/8/52 HOSTID PTF RO98208 MULTI-TYPE X-RGP ENTRIES NOT UPPER CASED PER MSG ACF61013 PTF RO98324 TSO RECONNECT GETS IKJ603I AFTER RO96905 PTF RO98340 S0C4 IN SAFRT003 PKI SERVICES BASE64 DECODE PTF RO98419 CORRECT SEQUENCE NUMBERS IN ACFCFDE & ACFXLID ** PRP ** RO98548 ACFRPTRX S002-18 ABEND ON SYSPRINT PTF RO98598 ACF68001 ON GENCERT WITH ZERO IN ALTNAME IP PTF RO98633 PSWDREQ NOT ENFORCED ON OLDER LIDRECS; NO MSG ACF02037 PTF RO98637 DECOMP GETS ACF60036 AFTER COMPILE GETS ACF70057 PTF The CA RS 1711 service count for this release is 22

CA ACF2 2 CA RS 1711 List for FMID Description Type RO97779 CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD PTF RO97781 PROVIDE NEW FLAG IN LOGONID TO ONLY LOG MAINT ACCESSES PTF RO97810 215 USER RECORD SHOWS DATA FROM PRIOR LOGONID PTF RO97842 FAILED PROFILE CHANGE GETS RC 0 PTF RO97857 SAFHFACF CREATING INVALID RULES WHEN PATHS GREATER THAN 255 PTF RO97896 ACF70042 DURING COMPILE WITH RO96906 AND COMPDYN WITH WHEN ** PRP ** RO97911 PSCBUSER HAS >7BYTES AFTER RO96905 ON A PRE Z/OS 2.3 SYSTEM PTF RO97921 VALIDATE NON-APF MUSASS ADDRESS SPACE USE OF SUPERCALL PTF RO98008 FIX ACFGINTP PLIST TO INDICATE EXPANDED AND INCLUDE LENGTH ** PRP ** RO98081 PKI SERVICES - 8/8/52 HOSTID PTF RO98208 MULTI-TYPE X-RGP ENTRIES NOT UPPER CASED PER MSG ACF61013 PTF RO98324 TSO RECONNECT GETS IKJ603I AFTER RO96905 PTF RO98340 S0C4 IN SAFRT003 PKI SERVICES BASE64 DECODE PTF RO98419 CORRECT SEQUENCE NUMBERS IN ACFCFDE & ACFXLID ** PRP ** RO98548 ACFRPTRX S002-18 ABEND ON SYSPRINT PTF RO98598 ACF68001 ON GENCERT WITH ZERO IN ALTNAME IP PTF RO98633 PSWDREQ NOT ENFORCED ON OLDER LIDRECS; NO MSG ACF02037 PTF RO98637 DECOMP GETS ACF60036 AFTER COMPILE GETS ACF70057 PTF The CA RS 1711 service count for this FMID is 18

CA ACF2 3 CA RS 1711 List for CAX1G01 FMID Description Type CAX1G01 RO97933 JES2 EXIT4 AND EXIT54 OUT-OF-SYNCH AFTER RO93512 ** PRP ** The CA RS 1711 service count for this FMID is 1

CA ACF2 4 CA RS 1711 List for FMID Description Type RO97780 CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD PTF The CA RS 1711 service count for this FMID is 1

CA ACF2 5 CA RS 1711 List for CAX1G04 FMID Description Type CAX1G04 RO93852 ACF2/IMS SUPPORT FOR IMS R15 PTF The CA RS 1711 service count for this FMID is 1

CA ACF2 6 CA RS 1711 List for CAX1G05 FMID Description Type CAX1G05 RO93853 ACF2/IMS SUPPORT FOR IMS R15 PTF The CA RS 1711 service count for this FMID is 1

CA ACF2 16.0 7 CA RS 1711 - PTF RO93852 RO93852 RO93852 M.C.S. ENTRIES = ++PTF (RO93852) ACF2/IMS SUPPORT FOR IMS R15 IBM has released IMS V15. The solutions for this problem provide support for IMS V15 in the CA ACF2 for z/os IMS option under ACF2. Not applicable Without this support, the ACF2 IMS interface will not function in an IMS V15 environment. Not applicable. CA-ACF2-MVS Release 16.0 CA-ACF2-MVS Release 15.0 ACF2MS 9955 Copyright (C) 2017 CA. All rights reserved. R00230-ACF160-SP1 DESC(ACF2/IMS SUPPORT FOR IMS R15 FMID (CAX1G04) PRE ( RO87169 ) SUP ( TR93852 ) ++IF FMID(CAX1G05) REQ(RO93853 ). ++HOLD (RO93852) SYSTEM FMID(CAX1G04) REASON (DYNACT ) DATE (17298) CA-ACF2-MVS IMS Version 16.0 PURPOSE Activate change without IPL USERS All users 1. LLA Refresh. 2. Stop and restart affected IMS V15 regions.

CA ACF2 16.0 8 CA RS 1711 - PTF RO93853 RO93853 RO93853 M.C.S. ENTRIES = ++PTF (RO93853) ACF2/IMS SUPPORT FOR IMS R15 IBM has released IMS V15. The solutions for this problem provide support for IMS V15 in the CA ACF2 for z/os IMS option under ACF2. Not applicable Without this support, the ACF2 IMS interface will not function in an IMS V15 environment. Not applicable. CA-ACF2-MVS Release 16.0 CA-ACF2-MVS Release 15.0 ACF2MS 9955 Copyright (C) 2017 CA. All rights reserved. R00230-ACF160-SP1 DESC(ACF2/IMS SUPPORT FOR IMS R15 FMID (CAX1G05) PRE ( RO89873 RO90019 ) SUP ( TR93851 TR93853 ) ++IF FMID(CAX1G04) REQ(RO93852 ). ++HOLD (RO93853) SYSTEM FMID(CAX1G05) REASON (DYNACT ) DATE (17298) CA-ACF2-MVS DLI Version 16.0 PURPOSE Activate change without IPL USERS All users 1. Please follow the Batch IMS install steps in the manual.

CA ACF2 16.0 9 CA RS 1711 - PTF RO97779 RO97779 RO97779 M.C.S. ENTRIES = ++PTF (RO97779) CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD Two issues are addressed: 1) Add support for new PWCNVRT keyword on CHANGE command. PWCNVRT will convert the current password to the current encryption level, as long as the current level is higher. The current encryption level is defined in the GSO PSWD PSWDENCT field. 2) Applications such as CICS TS that utilize the R_password evaluate callable service for password revalidation may consider normal passwords as valid even though the user should be required to use MFA or AAM or some other advanced authentication technique that was enforced at LOGON time. 2) Vary depending on environment. 2) Incomplete password reverification None CA-ACF2-MVS Version 16.0 ACF2MS 10011 Copyright (C) 2017 CA. All rights reserved. R00344-ACF160-SP1 DESC(CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD FMID () PRE ( RO80009 RO80085 RO80309 RO80625 RO80764 RO81740 RO84555 RO84559 RO84842 RO84877 RO84952 RO85672 RO87790 RO89360 RO91120 RO91169 RO92311 RO92400 RO92884 RO93240 RO93511 RO93554 RO95203 RO95460 RO95461 RO96464 RO96905 RO96906 RO96914 RO97094 RO97388 RO97777 ) SUP ( AR96905 AR97388 BR95461 HC87799 IC87799 RO80418 RO80735 RO85623 RO89222 RO91396 RO91401 RO91939 RO93301 RO93303 RO95192 RO95642 RO96880 RO97073 RO97101 RO97183 RO97666 RO97763 TR80411 TR80418 TR80735 TR85623 TR89222 TR91396 TR91401 TR91939 TR93301 TR93303 TR95192 TR95607 TR95642 TR96880 TR97073 TR97101 TR97111 TR97183 TR97184 TR97564 TR97585 TR97664 TR97666 TR97763 TR97779 ) ++IF FMID() REQ(RO97780 ). ++HOLD (RO97779) SYSTEM FMID() REASON (DYNACT ) DATE (17276) PURPOSE Activate change USERS All users

CA ACF2 16.0 10 CA RS 1711 - PTF RO97779 1. Reassemble the ACFFDR ++HOLD (RO97779) SYSTEM FMID() REASON (IPL ) DATE (17276) PURPOSE Activate change USERS All users 1. Reassemble the ACFFDR 2. IPL CLPA

CA ACF2 16.0 11 CA RS 1711 - PTF RO97780 RO97780 RO97780 M.C.S. ENTRIES = ++PTF (RO97780) CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD Two issues are addressed: 1) Add support for new PWCNVRT keyword on CHANGE command. PWCNVRT will convert the current password to the current encryption level, as long as the current level is higher. The current encryption level is defined in the GSO PSWD PSWDENCT field. 2) Applications such as CICS TS that utilize the R_password evaluate callable service for password revalidation may consider normal passwords as valid even though the user should be required to use MFA or AAM or some other advanced authentication technique that was enforced at LOGON time. 2) Vary depending on environment. 2) Incomplete password reverification None CA-ACF2-MVS Version 16.0 ACF2MS 10011 Copyright (C) 2017 CA. All rights reserved. R00344-ACF160-SP1 DESC(CONVERT PASSWORD TO HIGHER ENCRYPTION LEVEL/AAM R_PASSWORD FMID () PRE ( RO84878 ) SUP ( TR97112 TR97185 TR97565 TR97586 TR97780 ) ++IF FMID() REQ(RO97779 ). ++HOLD (RO97780) SYSTEM FMID() REASON (DYNACT ) DATE (17276) CA-ACF2-MVS CICS Version 16.0 PURPOSE Activate change USERS All users 1. Reassemble the ACFFDR ++HOLD (RO97780) SYSTEM FMID() REASON (IPL ) DATE (17276) CA-ACF2-MVS CICS Version 16.0

CA ACF2 16.0 12 CA RS 1711 - PTF RO97780 PURPOSE Activate change USERS All users 1. Reassemble the ACFFDR 2. IPL CLPA

CA ACF2 16.0 13 CA RS 1711 - PTF RO97781 RO97781 RO97781 M.C.S. ENTRIES = ++PTF (RO97781) PROVIDE NEW FLAG IN LOGONID TO ONLY LOG MAINT ACCESSES Enhancement Description: Provide a new LOGONID field called MAINTTRC. When MAINTTRC is turned on in a logonid it will cause an SMF record to be cut for every access that was allowed due to the access matching a MAINT environment. This means the access matched a MAINT record and the userid had either MAINT or NON-CNCL turned on. In this case we allow access with no logging. This new flag will now log these accesses allowing a site to run the ACFRPTDS report, looking for the MANT-PGM accesses and possibly write rules for all these accesses in order to remove the MAINT record. CA-ACF2-MVS Version 16.0 ACF2MS 10035 Copyright (C) 2017 CA. All rights reserved. R00345-ACF160-SP1 DESC(PROVIDE NEW FLAG IN LOGONID TO ONLY LOG MAINT ACCESSES FMID () PRE ( RO84555 RO84842 RO92884 RO95220 RO96905 RO97777 RO97779 ) SUP ( AR96905 RO97101 TR97101 TR97452 TR97625 TR97781 )

CA ACF2 16.0 14 CA RS 1711 - PTF RO97810 RO97810 RO97810 M.C.S. ENTRIES = ++PTF (RO97810) 215 USER RECORD SHOWS DATA FROM PRIOR LOGONID There could be a situation where the output from the ACFESAGE utility produces 215 USER records that contain data in some fields that belong to other logonids. The problem happens due to variable length logonids in the backup sequential database. The utility is not clearing out the read buffer in between reads. Thus if a prior logonid had data beyond the length of the current logonid being processed we would pick up the prior logonid data for the current user. This fix will also correct a possible S0C1 abend in ACFESAGE if a site has a user defined multi-valued field in the logonid. Invalid data produced in the 215 records. Utility cannot be used. None CA-ACF2-MVS Version 16.0 ACF2MS 10039 Copyright (C) 2017 CA. All rights reserved. R00346-ACF160-SP1 DESC(215 USER RECORD SHOWS DATA FROM PRIOR LOGONID FMID () PRE ( RO80625 RO84877 RO88324 RO92424 RO93554 RO96113 RO96114 RO96905 RO96906 RO96914 RO97148 ) SUP ( RO93116 TR78875 TR78890 TR93116 TR97810 ) ++HOLD (RO97810) SYSTEM FMID() REASON (DYNACT ) DATE (17276) PURPOSE Dynamic installation of this fix. USERS All users. KNOWLEDGE Operator commands. ACCESS z/os Operator console. 1. Perform an LLA REFRESH.

CA ACF2 16.0 15 CA RS 1711 - PTF RO97842 RO97842 RO97842 M.C.S. ENTRIES = ++PTF (RO97842) FAILED PROFILE CHANGE GETS RC 0 There are certain cases where failed CHANGE subcommands get return code 0 instead of return code 4. This situation happens when: 1) The CHANGE subcommand is issued in ACF mode 2) The CHANGE specifies a user profile field name (i.e. PWPHRASE) 3) The CHANGE command fails because of an invalid user profile field value Return code is zero when an ACF CHANGE subcommand fails while attempting to change a user profile field. Security administrator may not recognize that a CHANGE subcommand failed. Correct the CHANGE subcommand CA-ACF2-MVS Release 16.0 ACF2MS 10045 Copyright (C) 2017 CA. All rights reserved. R00348-ACF160-SP1 DESC(FAILED PROFILE CHANGE GETS RC 0 FMID () PRE ( RO84877 RO84952 RO97779 ) SUP ( RO80418 TR80418 TR97842 ) ++HOLD (RO97842) SYSTEM FMID() REASON (DYNACT ) DATE (17276) PURPOSE Activate change without IPL USERS All users LLA Refresh

CA ACF2 16.0 16 CA RS 1711 - PTF RO97857 RO97857 RO97857 M.C.S. ENTRIES = ++PTF (RO97857) SAFHFACF CREATING INVALID RULES WHEN PATHS GREATER THAN 255 The SAFHFACF conversion utility will create invalid rules in the output when there are USS pathnames greater than 255 characters in length. Invalid rules created that cannot be used. Cannot run the SAFHFACF conversion utility None CA-ACF2-MVS Version 16.0 ACF2MS 10041 Copyright (C) 2017 CA. All rights reserved. R00349-ACF160-SP1 DESC(SAFHFACF CREATING INVALID RULES WHEN PATHS GREATER THAN 255 FMID () SUP ( RO97140 TR97140 TR97857 ) ++HOLD (RO97857) SYSTEM FMID() REASON (DYNACT ) DATE (17291) PURPOSE Activate change without IPL USERS All users 1. LLA Refresh if required

CA ACF2 16.0 17 CA RS 1711 - PTF RO97896 RO97896 RO97896 M.C.S. ENTRIES = ++PTF (RO97896) ACF70042 DURING COMPILE WITH RO96906 AND COMPDYN WITH WHEN Trying to compile a resource rule with the WHEN parm added by RO96906 gets ACF70042 for the WHEM parm. This will happen with the GSO RULEOPTS COMPDYN specified. ACF70042 2 INVALID PARAMETER - WHEN - COMPILER TERMINATING Cannot compile the rule. Change GSO RULEOPTS to NOCOMPDYN and F ACF2,REFRESH(ruleopts Then compile the rule. CA-ACF2-MVS Version 16.0 ACF2MS 10047 Copyright (C) 2017 CA. All rights reserved. R00350-ACF160-SP1 DESC(ACF70042 DURING COMPILE WITH RO96906 AND COMPDYN WITH WHEN FMID () PRE ( RO96906 ) SUP ( AR89700 AR96906 RO89700 RO91069 TR89700 TR91069 TR97896 ) ++HOLD (RO97896) SYSTEM FMID() REASON (DYNACT ) DATE (17277) PURPOSE Activate change without IPL USERS All users 1. F LLA,REFRESH

CA ACF2 16.0 18 CA RS 1711 - PTF RO97911 RO97911 RO97911 M.C.S. ENTRIES = ++PTF (RO97911) PSCBUSER HAS >7BYTES AFTER RO96905 ON A PRE Z/OS 2.3 SYSTEM After applying RO96905 on a pre z/os 2.3 system, the PSCBUSER field will contain '>7BYTES' when the logonid on a batch tmp job is 8 characters long. Prior to the fix being applied the field would be blanks. The field is a seven character field and when the logonid is 8 characters, the field is blank filled. How this was reported was that sites have REXX execs that run in a batch tmp(ikjeft01) job and use %SYSUID. It is this %SYSUID that will contain the '>7BYTES' in this case. %SYSUID was blanks prior to RO96905 Get incorrect results if trying to use %SYSUID None CA-ACF2-MVS Version 16.0 ACF2MS 10048 Copyright (C) 2017 CA. All rights reserved. R00351-ACF160-SP1 DESC(PSCBUSER HAS >7BYTES AFTER RO96905 ON A PRE Z/OS 2.3 SYSTEM FMID () PRE ( RO96905 ) SUP ( BR96905 RO97509 TR97509 TR97911 ) ++HOLD (RO97911) SYSTEM FMID() REASON (DYNACT ) DATE (17276) PURPOSE Activate change without an IPL USERS All users 1. LLA REFRESH 2. F ACF2,NEWMOD(ACF00SVA)

CA ACF2 16.0 19 CA RS 1711 - PTF RO97921 RO97921 RO97921 M.C.S. ENTRIES = ++PTF (RO97921) VALIDATE NON-APF MUSASS ADDRESS SPACE USE OF SUPERCALL A new GSO OPTS option is being created: SUPERVAL NOSUPERVAL ---------- If SUPERVAL is set, SUPERCALL use by non-apf MUSASS address spaces will have a rule validation performed against the SUPERCAL Resource Class, with a resource name of logonid.supercall. The SUPERCAL Resource Class is defined to use the SPC Resource Type. The SERVICE for the access will be READ or UPDATE, based on the service requested by the SVC-A SUPERCALL issued. An example resource rule for SUPERCALL validation is: $KEY(logonid) TYPE(SPC) SUPERCALL UID(*) SERVICE(READ) ALLOW Failure of the validation will be accompanied by message: ACF00010 SUPERCALL not allowed for MUSASS lid llllllll None Varies depending on local use of MUSASS attribute and SUPERCALL. None ACF2MS 10038 Copyright (C) 2017 CA. All rights reserved. R00352-ACF160-SP1 DESC(VALIDATE NON-APF MUSASS ADDRESS SPACE USE OF SUPERCALL FMID () PRE ( RO80625 RO81740 RO81866 RO84877 RO84952 RO87405 RO87790 RO88654 RO89101 RO89360 RO89501 RO91913 RO92400 RO92884 RO96914 RO97777 RO97779 ) SUP ( TR97921 ) ++HOLD (RO97921) SYSTEM FMID() REASON (IPL ) DATE (17291) PURPOSE Enable new code USERS All users KNOWLEDGE IPL ACCESS IPL This change not in effect until after IPL with CLPA

CA ACF2 16.0 20 CA RS 1711 - PTF RO97933 RO97933 RO97933 M.C.S. ENTRIES = ++PTF (RO97933) JES2 EXIT4 AND EXIT54 OUT-OF-SYNCH AFTER RO93512 Reporting of JOBFROM use installed by PTF RO93512 may be incorrect for jobs submitted by card readers, RJE, SNA and BSC NJE, and SPOOL reload. Incorrect Submittor's LOGONID reported for JOBFROM use. JOBFROM use tracking and reporting only. None ACF2MS 10046 Copyright (C) 2017 CA. All rights reserved. R00353-ACF160-SP1 DESC(JES2 EXIT4 AND EXIT54 OUT-OF-SYNCH AFTER RO93512 FMID (CAX1G01) PRE ( RO91121 RO93512 RO97122 ) SUP ( BR93512 TR93509 TR97933 ) ++HOLD (RO97933) SYSTEM FMID(CAX1G01) REASON (DYNACT ) DATE (17298) CA-ACF2-MVS JES2 Version 16.0 PURPOSE Enable new code USERS All JES2 users KNOWLEDGE MVS Console ACCESS MVS Console 1. Issue console command 'F LLA,REFRESH'. 2. Issue console command '$TLOADMOD(ACFJ2ITF),REFRESH'. For full JOBFROM support, this SYSMOD must be installed on all connected JES2 systems.

CA ACF2 16.0 21 CA RS 1711 - PTF RO98008 RO98008 RO98008 M.C.S. ENTRIES = ++PTF (RO98008) FIX ACFGINTP PLIST TO INDICATE EXPANDED AND INCLUDE LENGTH The Dataset Encryption Support fix (RO96906) added a new field to the ACFGINTP resource rule interpreter parameter list. However, the ACFGINTP contains no flag indicator or length value that allows the rule interpreter to determine if the new field was properly passed by the caller. This fix updates the distributed ACFGINTP DSECT to define a bit flag and length value that can be checked to determine if the rule interpreter caller passed an expanded ACFGINTP PLIST. After application of RO96906 resource rules compiled with the RULELONG compiler are not interpreted correctly. Impact varies depending on the type of resource being checked. One known impact is that resource rules for PRIV-CTL processing do not work correctly. If possible, recompile failing resource rules with a $NORULELNG control statement. CA-ACF2-MVS Release 16.0 ACF2MS 10051 Copyright (C) 2017 CA. All rights reserved. R00355-ACF160-SP1 DESC(FIX ACFGINTP PLIST TO INDICATE EXPANDED AND INCLUDE LENGTH FMID () PRE ( RO80628 RO81740 RO81866 RO88622 RO96906 ) SUP ( BR96906 TR98008 ) ++HOLD (RO98008) SYSTEM FMID() REASON (DYNACT ) DATE (17298) PURPOSE Activate change without IPL USERS All users 1. LLA Refresh 2. Execute console command 'F ACF2,NEWMOD(ACF00SVA)' 3. Execute console command 'F ACF2,NEWMOD(ACF9C000)'

CA ACF2 16.0 22 CA RS 1711 - PTF RO98081 RO98081 RO98081 M.C.S. ENTRIES = ++PTF (RO98081) PKI SERVICES - 8/8/52 HOSTID An attempt to generate a certificate using PKI s failed with 8/8/52 - Diaginfo HostID The error occurs when %%HostIdMap=@host-name%% is specified in the template being used when host-name does not contain a period. No certificate can be generated using that template None CA-ACF2-MVS Version 16.0 ACF2MS 10042 Copyright (C) 2017 CA. All rights reserved. R00356-ACF160-SP1 DESC(PKI SERVICES - 8/8/52 HOSTID FMID () PRE ( RO95082 ) SUP ( RO95058 RO95851 TR95058 TR95851 TR98081 ) ++HOLD (RO98081) SYSTEM FMID() REASON (DYNACT ) DATE (17276) PURPOSE Activate change without IPL USERS All users of the R_PKIServ (IRRSPX00/IRRSPX64) service 1. LLA Refresh 2. Execute console command 'F ACF2,NEWMOD(SAFRT003)'

CA ACF2 16.0 23 CA RS 1711 - PTF RO98208 RO98208 RO98208 M.C.S. ENTRIES = ++PTF (RO98208) MULTI-TYPE X-RGP ENTRIES NOT UPPER CASED PER MSG ACF61013 In the CA ACF2 product documentation of the Resource Group Cross-reference (X-RGP) record, there is a note related to the TYPE(code) parameter: Note: For mixed-case resource TYPEs, the INCLUDE and EXCLUDE values must be typed in mixed case. Use only one kind of TYPE code - mixed case or non-mixed case - for each X(RGP) record. If the TYPE keyword contains both mixed case types and non-mixed case types, the INCLUDE and EXCLUDE lists are upper cased by the ACF command processor. However, if the TYPE keyword contains both mixed case types and non-mixed case types, the INCLUDE and EXCLUDE lists are upper cased by the ACF command processor only on CHANGE sub-commands, not on INSERT sub-commands. In addition, the message indicating that this was being done was only issued on INSERT: ACF61013 MIXED CASE AND NON-MIXED CASE RESOURCE TYPES SPECIFIED, INCLUDE/EXCLUDE LISTS WILL BE UPPER CASED To make this processing consistent, the INCLUDE and EXCLUDE lists will no longer be upper cased at all. Message ACF61013 issued but no upper casing was performed. Message ACF61013 not issued but upper casing was performed. Varies depening on local implementation of X-RGP records. None ACF2MS 10049 Copyright (C) 2017 CA. All rights reserved. R00357-ACF160-SP1 DESC(MULTI-TYPE X-RGP ENTRIES NOT UPPER CASED PER MSG ACF61013 FMID () PRE ( RO84877 RO84952 RO89501 RO91169 RO92884 RO95905 RO96914 ) SUP ( TR98208 ) ++HOLD (RO98208) SYSTEM FMID() REASON (DYNACT ) DATE (17303) PURPOSE Enable new code without IPL USERS All users KNOWLEDGE z/os Console commands ACCESS z/os Console 1. Issue: F LLA,REFRESH 2. Issue: F ACF2,NEWMOD(ACF00SVA)

CA ACF2 16.0 24 CA RS 1711 - PTF RO98324 RO98324 RO98324 M.C.S. ENTRIES = ++PTF (RO98324) TSO RECONNECT GETS IKJ603I AFTER RO96905 With RO96905 (support for 8 character TSO userids) it is possible for a TSO RECONNECT logon to fail with message message IKJ603I. IKJ603I TSOLOGON TERMINATED. INSTALLATION EXIT ERROR 056 TSO RECONNECT LOGON fails None. CA-ACF2-MVS Version 16.0 ACF2MS 10054 Copyright (C) 2017 CA. All rights reserved. R00359-ACF160-SP1 DESC(TSO RECONNECT GETS IKJ603I AFTER RO96905 FMID () PRE ( RO96905 ) SUP ( TR98324 ) ++HOLD (RO98324) SYSTEM FMID() REASON (IPL ) DATE (17278) PURPOSE Activate change USERS All users Perform an IPL with CLPA

CA ACF2 16.0 25 CA RS 1711 - PTF RO98340 RO98340 RO98340 M.C.S. ENTRIES = ++PTF (RO98340) S0C4 IN SAFRT003 PKI SERVICES BASE64 DECODE When running PKI s and attempting the EXPORT function it is possible for an 0C4 abend to occur in module SAFRT003. 0C4 ABEND in module SAFRT003 The user cannot successfully complete PKI s EXPORT function None. CA-ACF2-MVS Version 16.0 ACF2MS 10053 Copyright (C) 2017 CA. All rights reserved. R00360-ACF160-SP1 DESC(S0C4 IN SAFRT003 PKI SERVICES BASE64 DECODE FMID () PRE ( RO95082 ) SUP ( RO95058 RO95851 RO98081 TR95058 TR95851 TR98081 TR98340 ) ++HOLD (RO98340) SYSTEM FMID() REASON (DYNACT ) DATE (17298) PURPOSE Activate change without IPL USERS All users of the R_PKIServ (IRRSPX00/IRRSPX64) service 1. LLA Refresh 2. Execute console command 'F ACF2,NEWMOD(SAFRT003)'

CA ACF2 16.0 26 CA RS 1711 - PTF RO98419 RO98419 RO98419 M.C.S. ENTRIES = ++PTF (RO98419) CORRECT SEQUENCE NUMBERS IN ACFCFDE & ACFXLID The ACFCFDE and ACFXLID macros distributed in RO97781 have incorrect sequence numbers. This fix corrects the sequence numbers. Local USERMODs to update ACF2 code no longer fit because SMP IEBUPDTE processing fails: INVALID OPERATION. TERMINATED THIS MEMBER. IEBUPDTE WILL TRY NEXT MEMBER. HIGHEST CONDITION CODE WAS 00000004 END OF JOB IEBUPDTE. Delay in installation of maintenence. None CA-ACF2-MVS Version 16.0 ACF2MS 10056 Copyright (C) 2017 CA. All rights reserved. R00361-ACF160-SP1 DESC(CORRECT SEQUENCE NUMBERS IN ACFCFDE & ACFXLID FMID () PRE ( RO84555 RO84842 RO92884 RO96905 RO97777 RO97779 RO97781 ) SUP ( AR96905 AR97781 RO97101 TR97101 TR98419 ) ++HOLD (RO98419) SYSTEM FMID() REASON (DYNACT ) DATE (17298) PURPOSE Activate change USERS All users with RO97781 1. Reassemble ACFFDR 2. LLA REFRESH 3. F ACF2,NEWMOD(ACFFDR)

CA ACF2 16.0 27 CA RS 1711 - PTF RO98548 RO98548 RO98548 M.C.S. ENTRIES = ++PTF (RO98548) ACFRPTRX S002-18 ABEND ON SYSPRINT When running ACFRPTRX it is possible that an S002-18 ABEND will occur when writing a line of output to the SYSPRINT DD. The problem may also show up as an 0C4 abend in ACF4AINT. Message IEC036I 002-18 is issued indicating a failed attempt to write a record to SYSPRINT. An 0C4 abend in ACF4AINT may also be a symptom of this problem. Users cannot run ACFRPTRX None CA-ACF2-MVS Version 16.0 ACF2MS 10055 Copyright (C) 2017 CA. All rights reserved. R00363-ACF160-SP1 DESC(ACFRPTRX S002-18 ABEND ON SYSPRINT FMID () PRE ( RO83659 ) SUP ( TR98548 ) ++HOLD (RO98548) SYSTEM FMID() REASON (DYNACT ) DATE (17290) PURPOSE Activate change without IPL USERS All ACFRPTRX users LLA Refresh

CA ACF2 16.0 28 CA RS 1711 - PTF RO98598 RO98598 RO98598 M.C.S. ENTRIES = ++PTF (RO98598) ACF68001 ON GENCERT WITH ZERO IN ALTNAME IP When the GENCERT subcommand is issued with an ALTNAME IP address parameter that specifies an IPV4 address with zero in one of the four IPV4 address sections the command fails with message ACF68001. The GENCERT subcommand fails with an ACF68001 message similar to this: ACF68001 The 141.202.0.39 value specified is invalid ACF2 administration cannot successfully issue the GENCERT If possible, avoid using an IP with zero in the ALTNAME parameter of GENCERT CA-ACF2-MVS Version 16.0 ACF2MS 10059 Copyright (C) 2017 CA. All rights reserved. R00366-ACF160-SP1 DESC(ACF68001 ON GENCERT WITH ZERO IN ALTNAME IP FMID () SUP ( TR98598 ) ++HOLD (RO98598) SYSTEM FMID() REASON (DYNACT ) DATE (17298) PURPOSE Activate change without IPL USERS All users LLA Refresh

CA ACF2 16.0 29 CA RS 1711 - PTF RO98633 RO98633 RO98633 M.C.S. ENTRIES = ++PTF (RO98633) PSWDREQ NOT ENFORCED ON OLDER LIDRECS; NO MSG ACF02037 With PSWDREQ in effect, when RESTRICT is removed from a LOGONID the LOGONID is not to be left without a password. In this case message 'ACF02037 KEYWORD PASSWORD IS REQUIRED' is returned in response to the 'CHANGE lid NORESTRICT' subcommand. For older LOGONIDs, the internal area where the AES1 password is now stored my contain residual spaces. These spaces may be erroneously interpreted by the validation code as an AES1 password, allowing the RESTRICT attribute to be removed even though the LOGONID does not have a valid password. PSWDREQ may not be enforced in some cases. LOGONID left without a password. Assign a password to the LOGONID. ACF2MS 10036 Copyright (C) 2017 CA. All rights reserved. R00367-ACF160-SP1 DESC(PSWDREQ NOT ENFORCED ON OLDER LIDRECS; NO MSG ACF02037 FMID () PRE ( RO84877 RO84952 RO91169 RO95461 RO96905 RO97388 RO97779 ) SUP ( TR98306 TR98633 ) ++HOLD (RO98633) SYSTEM FMID() REASON (DYNACT ) DATE (17303) PURPOSE Enable new code without IPL USERS All users KNOWLEDGE z/os Console commands ACCESS z/os Console 1. Issue: F LLA,REFRESH 2. Issue: F ACF2,NEWMOD(ACF00SVA)

CA ACF2 16.0 30 CA RS 1711 - PTF RO98637 RO98637 RO98637 M.C.S. ENTRIES = ++PTF (RO98637) DECOMP GETS ACF60036 AFTER COMPILE GETS ACF70057 When a ROLESET access rule is compiled the rule compiler may issue message 'ACF70057 IN ONE OR MORE RULES, ROLE OR USER CONTAINS A LITERAL ASTERISK OR DASH CHARACTER' to alert the user that the asterisk or dash character will be treated as a literal, not a mask. After message ACF70057 is issued, subsequent attempts to decompile the rule fail with message 'ACF60036 OUTPUT BUFFER TOO SMALL'. DECOMP command gets the following error: ACF60036 OUTPUT BUFFER TOO SMALL Security administrators cannot decompile a ROLESET rule after message ACF70057 Get out of the ACF command, then get back into ACF and issue the DECOMP command against the ROLESET rule CA-ACF2-MVS Version 16.0 ACF2MS 10061 Copyright (C) 2017 CA. All rights reserved. R00369-ACF160-SP1 DESC(DECOMP GETS ACF60036 AFTER COMPILE GETS ACF70057 FMID () PRE ( RO96906 ) SUP ( TR98637 ) ++HOLD (RO98637) SYSTEM FMID() REASON (DYNACT ) DATE (17298) PURPOSE Activate change without IPL USERS All users LLA Refresh

CA ACF2 16.0 31 CA RS 1711 Product/Component Listing Product Family Product Release Security CA-ACF2-MVS 16.00.00 CA MAINFRAME ADVANCED AUTHENTICATION 02.00.00 The CA RS 1711 Product/Component Count for this release is 2

CA ACF2 16.0 32 All CA RS Levels List CA RS Level FMID CAR1711 RO98637 RO98633 RO98598 RO98548 RO98419 RO98340 RO98324 RO98208 RO98081 RO98008 RO97933 RO97921 RO97911 RO97896 RO97857 RO97842 RO97810 RO97781 RO97780 RO97779 RO93853 RO93852 CAX1G01 CAX1G05 CAX1G04 CAR1710 RO97939 RO97830 RO97778 RO97777 RO97763 CAR1709 RO97666 RO97509 RO97388 RO97374 RO97246 RO97234 RO97148 RO97142 RO96914 RO96906 CAR1708 RO97183 RO97140 RO97123 RO97122 RO97101 RO97094 RO97073 RO97057 RO96917 RO96905 RO96890 RO96880 RO96870 RO96854 RO96794 RO96729 RO96676 CAX1G02 CAX1G01 RO96443

CA ACF2 16.0 33 All CA RS Levels List CA RS Level FMID RO96422 RO96075 RO96003 RO95963 RO95859 RO95851 RO95721 RO95562 RO95461 RO95460 RO95220 RO94330 RO93635 RO93566 RO93513 RO93512 RO93511 CAX1G02 CAX1G01 CAR1707 RO96464 RO96074 RO95905 RO95735 RO95642 RO95610 RO95144 CAR1706 RO96114 RO96113 RO96094 RO95936 RO95586 RO95350 RO93988 CAR1705 RO95841 RO95836 RO95608 RO95521 RO95459 RO95456 RO95219 RO95218 RO95203 RO95192 RO95082 RO94381 RO93881 RO93615 RO93394 RO92798 CAX1G04 CAR1704 RO95320 RO95173 RO95168 RO95122 RO95058 RO94877 RO94841 RO94796

CA ACF2 16.0 34 All CA RS Levels List CA RS Level FMID RO94697 RO94599 RO94543 RO94309 RO93699 RO93380 RO91983 CAR1703 RO94325 RO94125 RO93581 CAR1702 RO93738 RO93181 CAR1701 RO93554 RO93442 RO93377 RO93303 RO93301 RO93240 RO92540 RO92536 CAR1612 RO93116 RO93003 RO92884 RO91980 RO91338 RO91271 RO91194 RO91069 CAX1G02 CAR1611 RO92541 RO92424 RO92400 RO92311 RO91913 RO90077 CAR1610 RO92184 RO92080 RO91962 RO91939 RO91578 RO91396 RO90020 RO90019 RO89873 RO88622 CAX1G05 CAX1G05 CAX1G05 CAR1609 RO91401 RO91270 RO91169 RO91121 RO91120 RO89763 CAX1G01 CAR1607 RO90749 RO90415 CAR1606 RO90049 RO89700 RO89501

CA ACF2 16.0 35 All CA RS Levels List CA RS Level FMID RO89393 RO89101 RO89039 CAR1605 RO89649 RO89603 RO89602 RO89442 RO89397 RO89396 RO89360 RO89274 RO89222 RO88971 RO88719 RO88654 RO88324 RO88106 RO87944 RO87169 RO86948 CAX1G04 CAR1604 RO89184 RO89120 RO89117 RO89116 RO88717 RO88240 RO87405 RO87013 RO86545 CAR1603 RO88319 RO87790 RO86551 RO86548 RO86546 CAR1602 RO87685 RO87221 RO86888 RO86762 RO86681 RO86542