On Wed, 13 May 2009 10:33:19 -0500, Walt Farrell <wfarr...@us.ibm.com> wrote:
a) use RACROUTE REQUEST=AUTH, from an APF-authorized program, specifying >ENTITY or ENTITYX=(resource-name-address,PRIVATE). RACF will return a >profile (still possibly one that's merged) but the name will be the member >name (possibly generic) that matched. You'll need to be in key 0 to examine >the returned data, and to FREEMAIN it. > This option worked great, thanks. >If your summary of historical access were based on RACF SMF records, of >course, you'd know the proper member name already from those records, and >wouldn't need to be trying to figure it out. > Pint was to recheck historical access after making changes, such as adding more explicit profiles, etc. That's why I wanted the profile matched. Also using LOG=NONE on my calls, as I didn't want to record these 'test' access on SMF. Thanks for your help. Joe ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to lists...@bama.ua.edu with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html