Thanks for the assistance. Yes, I had to define 2 CONNECT profiles to get it to work for now. I made them rather generic for now just to get the functionality working. I will go back later and make the profiles more discrete.
I did see the table in the 2.3.1 manual, that is where I saw it could be multiple CONNECT profiles. So for now when I get the C4R638I I will just need to "play" around to determine which profile is needed.
Now that we have Access Monitor running, I assume I could look at that data to see what resource it was trying to validate?
------------------------------
Linnea Sullivan
------------------------------
Original Message:
Sent: Thu March 05, 2020 04:47 AM
From: Rob van Hoboken
Subject: Determine Missing Authority when using CTLSPEC in Command Verifier
Hi Linnea
The DFTLGRP(DSAPP10) parameter implies creation of a connect to this group. Connects are controlled/protected by the C4R.CONNECT.ID.group.user policy profiles. Message C4R638I indicates that there is no profile for resource C4R.CONNECT.ID.DSAPP10.PWTEST04
Did you create a C4R.CONNECT.ID.** policy profile?
You are right, the value Group in msg C4R638I is somewhat generic, it would have been more helpful if the message had pointed to Dfltgrp, but then the message description should have pointed out that DFTLGRP leads to verification of several policies. Connect would lead to similar confusion.
The Command Verifier User Guide contains a table of the policies verified due to =CTLSPEC. Around page 50.