On Wed, 13 May 2009 10:33:19 -0500, Walt Farrell <wfarr...@us.ibm.com> 
wrote:

a) use RACROUTE REQUEST=AUTH, from an APF-authorized program, specifying
>ENTITY or ENTITYX=(resource-name-address,PRIVATE).  RACF will return a
>profile (still possibly one that's merged) but the name will be the member
>name (possibly generic) that matched.  You'll need to be in key 0 to examine
>the returned data, and to FREEMAIN it.
>
This option worked great, thanks.

>If your summary of historical access were based on RACF SMF records, of
>course, you'd know the proper member name already from those records, and
>wouldn't need to be trying to figure it out.
>

Pint was to recheck historical access after making changes, such as adding 
more explicit profiles, etc. That's why I wanted the profile matched. Also 
using 
LOG=NONE on my calls, as I didn't want to record these 'test' access on SMF.

Thanks for your help.

Joe

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@bama.ua.edu with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to