Thanks, makes a lot of sense, I'll pass that on to our RACF admin.

> -----Original Message-----
> From: The IBM z/VM Operating System [mailto:ib...@listserv.uark.edu] On
> Behalf Of Rob van der Heij
> Sent: Wednesday, June 10, 2009 3:31 PM
> To: IBMVM@LISTSERV.UARK.EDU
> Subject: Re: LOGONBY 8 user limitation
>
> On Wed, Jun 10, 2009 at 9:08 PM, Romanowski, John
> (OFT)<john.romanow...@cio.ny.gov> wrote:
>
> > PERMIT LOGONBY.PERFSVM  CLASS(SURROGAT) ID(STAFF1)   ACCESS(READ)
>
> Do yourself a favor and connect the various individuals to RACF groups
> and then permit these groups to the logonby profiles. Even when you
> have several people with different roles, the number of groups is
> probably pretty small. Doing so will make your life easier when people
> change roles in your shop.
> And it avoids the trouble when you want to delete a user and can't
> find the profile where he's still on the access list.
>
> -Rob


This e-mail, including any attachments, may be confidential, privileged or 
otherwise legally protected. It is intended only for the addressee. If you 
received this e-mail in error or from someone who was not authorized to send it 
to you, do not disseminate, copy or otherwise use this e-mail or its 
attachments.  Please notify the sender immediately by reply e-mail and delete 
the e-mail from your system.

Reply via email to