IBM Security Z Security

 View Only

How to keep the RACF "last access" field updated

  • 1.  How to keep the RACF "last access" field updated

    Posted Wed April 10, 2024 05:22 AM
    Hi everyone . Can I ask you for a possible solution regarding a specific need to keep the RACF "Last logged in" field updated (so as not to revoke the user for inactivity) even if the user is not logged in to z/OS. 
    This is a special case where some distributed user IDs are authenticated with RACF via Ldap using native authentication, but they are not z/OS user IDs but only Active Directory user IDs
    For example, what do you think about the use of RACINIT to automatically update the "last-access" field when the userid starts with ActiveDirectory->LDAP->RACF authentication, but without accessing z/OS?. I will appreciate  any idea or suggestion


    ------------------------------
    Luigi Perrone
    ------------------------------