Hi Linnea,
I attempted to recreate your scenario on one of my zSecure education systems.
I defined both the Command Verifier profiles C4R.JESSPOOL.ID.** (UACC NONE and no permission to my user ID) and C4R.JESSPOOL.ID.&RACLNDE.** (with my user ID on the ACL with UPDATE access).
Next, when I tried to define a JESSPOOL profile that was named &RACLNDE.myuserid.**, this define command was unsuccessful. The violation message that I received indicated that my user ID lacked the required UPDATE access to XFACILIT profile C4R.JESSPOOL.ID.**. This seems to indicate that indeed the ampersand in &RACLNDE is not working as you expected. According to me, in this profile Command Verifier treats the &RACLNDE value as a variable instead of as a literal.
However, when I replaced XFACILIT profile C4R.JESSPOOL.ID.&RACLNDE.** with C4R.JESSPOOL.ID.%RACLNDE.** and then tried to define JESSPOOL profile &RACLNDE.myuserid.** again, this command was successful. And attempting to define a JESSPOOL profile with a different hlq as &RACLNDE failed. If I understand you correctly, this is how you wanted this to work.
I understand that this does not explain why in your system you were authorized to define JESSPOOL profile
XXXXNODE.AK#TST.**, but in my opinion, it does illustrate that your scenario can work when you use XFACILIT profile C4R.JESSPOOL.ID.%RACLNDE.**.I read in your message that you also tried to define XFACILIT profile
C4R.JESSPOOL.%RACLNDE.**. I note that this profile lacks the ID qualifier. Is that just a typo or did your forget the ID qualifier in profile C4R.JESSPOOL.ID.%RACLNDE.**?
Hope this helps.
------------------------------
Tom Zeehandelaar
z/OS Security Enablement Specialist - zSecure developer
IBM
Delft
+31643351728
------------------------------