This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
Thank you for submitting this requirement. It is accepted as an Uncommitted Candidate.
Due to processing by IBM, this request was reassigned to have the following updated attributes:
Brand - Servers and Systems Software
Product family - z Systems Software
Product - z/OS
Component - RACF
Operating system - IBM z/OS
Source - None
For recording keeping, the previous attributes were:
Brand - Servers and Systems Software
Product family - z Systems Software
Product - z/OS
Component - USS
Operating system - IBM z/OS
Source - None
I'm confused by your response.
Are you saying you leave it up to the External Security Manager (ESM) to call itself?
In this case z/OS UNIX is the caller and it should do a better job of not "over calling" the ESM for every directory traverse etc.
We use RACF but regardless of ESM the coding job to be done here is clearly by z/OS UNIX development.
We meet regularly with Bruce Wells. He is our RACF Lab Advocate.
Please feel free to follow up with him with additional questions as he can help facilitate a meeting to further discuss this much needed requirement.
There are no additional access checks made by z/OS UNIX when
FSACCESS is enabled. There is additional checking done
by the security product. Please indicate which security
product you use so this can be properly routed.
it's a real "resource eater"
Hello, I agree completely with this findings. The overhead is very high.
I don´t know how this caching can be implemented (if possible). Based on Process-ID or Job or Jobstep or Userid or whatever?