IBM Security Z Security

Security for Z

Join this online user group to communicate across Z Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  CKGRACF LIST USER - MFA information

    Posted 06/30/23 06:57 AM

    Hi, 

    I have an application using 'CKGRACF LIST USER  userid  tag' command 

    Is there a way of including MFA information in the tagged output?



    ------------------------------
    James Lumsden
    ------------------------------


  • 2.  RE: CKGRACF LIST USER - MFA information

    Posted 06/30/23 09:17 AM

    Hi James,

    The CKGRACF LIST USER command has no support for MFA data.

    With CKGRACF CMD commands on the other hand, RACF LISTUSER and ALTUSER MFA commands can be issued.

    The CKGRACF FIELD command provides MFDATA (MFA segment free-form factor metadata) support,
    but this is primarily meant for execution of "Copy userid" actions issued from the zSecure UI.

    Regards,



    ------------------------------
    Luc Rutten
    Advisory Software Engineer, zSecure
    IBM
    Delft
    ------------------------------



  • 3.  RE: CKGRACF LIST USER - MFA information

    Posted 06/30/23 10:08 AM

    The CKGRACF FIELD … MFDATA command is rather meant for recreating general resource profiles-not for copying userids.

    Regards,



    ------------------------------
    Luc Rutten
    Advisory Software Engineer, zSecure
    IBM
    Delft
    ------------------------------



  • 4.  RE: CKGRACF LIST USER - MFA information

    Posted 07/04/23 03:49 AM

    Hi Luc, 
    Thanks for the response.

    It would be a really useful enhancement if the MFA data could be included in the output. I am specifically using the tag format to be parsed simply by a  distributed (unix) service.

    Candidate for an SPE?

    Thanks

     



    ------------------------------
    James Lumsden
    ------------------------------



  • 5.  RE: CKGRACF LIST USER - MFA information

    Posted 07/06/23 04:55 AM

    Hi James,

    LIST USER TAG support for MFA data is certainly a candidate for an SPE.
    Support for password fallback status, policies, and factors can be included.
    You are welcome to make a request on https://ideas.ibm.com/.

    Regards,



    ------------------------------
    Luc Rutten
    Advisory Software Engineer, zSecure
    IBM
    Delft
    ------------------------------