Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Not under consideration
Created by Guest
Created on Aug 9, 2023

WE REQUEST IBM TO CHANGE SECURITY IN WARN MODE - TO WRITE MESSAGE TO THE MQ LOG AS TO WHAT FAILURE HAS BEEN ALLOWED TO PROCEED IN WARN MODE

We implemented RESLEVEL on our z/OS QMGRs.    When in WARN MODE - With either RACF OR TOP SECRET  - AND THE USERID IS PERMITTED TO MAKE AN MQ UPDATE - IN WARM MODE - IT IS ALLOWED TO PROCEED WITH THE UPDATE BECAUSE IT IS IN WARN MODE.  IN THIS SCENARIO - WE DO NOT GET ANY MESSAGE IN OUR MQ LOG - WE REQUEST  IBM TO WRITE MESSAGE TO MQ LOG THAT THE UPDATE WAS ALLOWED TO OCCUR, BUT ALSO TO GENERATE A MESSAGE THAT STATES THE FUNCTION WAS ALLOWED, BUT TO MAKE THE PERMISSION SO THAT WHEN WARN MODE IS TURNED OFF -AND THE SECURITY ADMIN HAS PERMANENTLY ENABLED THE ID TO HAVE THE PROPER ACCESS.

Idea priority Medium
  • Admin
    Matthew Leming
    Reply
    |
    Sep 25, 2023

    Declining as there are messages in the log as shown above. Feel free to contact me directly to discuss more: lemingma@uk.ibm.com.

  • Admin
    Matthew Leming
    Reply
    |
    Aug 24, 2023

    Hello,

    MQ delegates this sort of thing to the ESM, so we wouldn't want to add a message to MQ.
    That said, on our system we get the following in MQ's MSTR joblog when WARNING is in place in RACF:

    14.34.21 STC06984 ICH408I USER(redacted ) GROUP(redacted) NAME(MATTHEW LEMING ) 309

    309 MQ21.DEFINE.NAMELIST CL(MQCMDS )

    309 WARNING: INSUFFICIENT AUTHORITY - TEMPORARY ACCESS ALLOWED

    309 ACCESS INTENT(ALTER ) ACCESS ALLOWED(NONE )

    Are you saying you don't get this? Are you issuing the MQSC command that you get a warning from?

    Regards, Matt.