<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNA RJE in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670066#M50659</link>
    <description>&amp;gt;Which RJE server are you using? Host based or &amp;gt;Gateway based? &lt;BR /&gt;Host based&lt;BR /&gt;&lt;BR /&gt;&amp;gt;How are the streams set up? &lt;BR /&gt;&amp;gt;Which directory is each stream (RD,PR, PU) &amp;gt;assigned to? &lt;BR /&gt;$MC SNARJE&lt;BR /&gt;USE MAIL&lt;BR /&gt;CLEAR WORK&lt;BR /&gt;SET WORKSTATION/GATEWAY=DIANE-&lt;BR /&gt;/ACCESS=MAILBOX/DATA=MR00022/SERVER=EAGLE&lt;BR /&gt;ASSIGN sys$sysdevice:[MAILBOX] PR1&lt;BR /&gt;ASSIGN MAIL$RD1 RD1&lt;BR /&gt;SET WORKSTATION/STATE=ON&lt;BR /&gt;SET MONI/PERM&lt;BR /&gt;EXIT&lt;BR /&gt;$SUBMIT/SNA/QUE=MAIL$RD1 DIR.JCL&lt;BR /&gt;$EXIT&lt;BR /&gt;&lt;BR /&gt;&amp;gt;The default account for FAL normally does &amp;gt;not have enough privileges to access files &amp;gt;for the above streams. You need to have &amp;gt;either proxy access set up for the RJE &amp;gt;server or set up proper access control for &amp;gt;the directories (where the streams are &amp;gt;assigned to).&lt;BR /&gt;sys$sysdevice:[mailbox] is set (w:rwed).  Did have a thought - the RJE work files are in the users directory - it would cause an issue if there was an attempt to access those with the default FAL account - migh this be the problem?  Any way to specify where rje places the work files?</description>
    <pubDate>Mon, 14 Nov 2005 09:13:37 GMT</pubDate>
    <dc:creator>David Kramer_2</dc:creator>
    <dc:date>2005-11-14T09:13:37Z</dc:date>
    <item>
      <title>SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670063#M50656</link>
      <description>Setting up RJE on a new machine (alpha, openvms 7.3-2, rje v.7)  Trying to do an RJE transaction and getting the following error:&lt;BR /&gt;-RMS-E-ACC, ACP file access failed&lt;BR /&gt;-SYSTEM-F-LINKEXIT, network partner exited&lt;BR /&gt;&lt;BR /&gt;I'm missing a permissions thing somewhere (I can give the default FAL account SYSPRV and the thing works fine, but I figure this is a bad thing)&lt;BR /&gt;&lt;BR /&gt;Directory that the JCL is in is W:RWED (as is it's parent directory) and I've gone so far as changing owner to the default FAL account.  It's been about 15 years since I've had to mess with this (and have problems remembering anything past last week)&lt;BR /&gt;&lt;BR /&gt;Thoughts as to what I'm missing? Thanks in advance for your help.</description>
      <pubDate>Fri, 11 Nov 2005 14:42:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670063#M50656</guid>
      <dc:creator>David Kramer_2</dc:creator>
      <dc:date>2005-11-11T14:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670064#M50657</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;check, if you have W:E for root 000000.dir. And all subdirs. W:RWED isn't necessary and wanted. &lt;BR /&gt;You can check netserver.log or net$server.log in FAL sys$login directory.&lt;BR /&gt;&lt;BR /&gt;You can also set auditing for &lt;BR /&gt;  FILE access:&lt;BR /&gt;    Failure:     read,write,execute,delete,control&lt;BR /&gt; &lt;BR /&gt;Or set auditing for only specified dir &lt;BR /&gt;$ set security jcl.dir /acl=          (AUDIT=SECURITY,ACCESS=WRITE+DELETE+CONTROL+SUCCESS+FAILURE)&lt;BR /&gt;&lt;BR /&gt;and check audit log.&lt;BR /&gt;&lt;BR /&gt;Mike</description>
      <pubDate>Fri, 11 Nov 2005 14:57:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670064#M50657</guid>
      <dc:creator>Mike Reznak</dc:creator>
      <dc:date>2005-11-11T14:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670065#M50658</link>
      <description>Hi David,&lt;BR /&gt;&lt;BR /&gt;Which RJE server are you using? Host based or Gateway based? How are the streams set up? Which directory is each stream (RD,PR, PU) assigned to? The default account for FAL normally does not have enough privileges to access files for the above streams. You need to have either proxy access set up for the RJE server or set up proper access control for the directories (where the streams are assigned to).&lt;BR /&gt;&lt;BR /&gt;Thanks and regards.&lt;BR /&gt;&lt;BR /&gt;Michael&lt;BR /&gt;</description>
      <pubDate>Sun, 13 Nov 2005 03:58:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670065#M50658</guid>
      <dc:creator>Michael Yu_3</dc:creator>
      <dc:date>2005-11-13T03:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670066#M50659</link>
      <description>&amp;gt;Which RJE server are you using? Host based or &amp;gt;Gateway based? &lt;BR /&gt;Host based&lt;BR /&gt;&lt;BR /&gt;&amp;gt;How are the streams set up? &lt;BR /&gt;&amp;gt;Which directory is each stream (RD,PR, PU) &amp;gt;assigned to? &lt;BR /&gt;$MC SNARJE&lt;BR /&gt;USE MAIL&lt;BR /&gt;CLEAR WORK&lt;BR /&gt;SET WORKSTATION/GATEWAY=DIANE-&lt;BR /&gt;/ACCESS=MAILBOX/DATA=MR00022/SERVER=EAGLE&lt;BR /&gt;ASSIGN sys$sysdevice:[MAILBOX] PR1&lt;BR /&gt;ASSIGN MAIL$RD1 RD1&lt;BR /&gt;SET WORKSTATION/STATE=ON&lt;BR /&gt;SET MONI/PERM&lt;BR /&gt;EXIT&lt;BR /&gt;$SUBMIT/SNA/QUE=MAIL$RD1 DIR.JCL&lt;BR /&gt;$EXIT&lt;BR /&gt;&lt;BR /&gt;&amp;gt;The default account for FAL normally does &amp;gt;not have enough privileges to access files &amp;gt;for the above streams. You need to have &amp;gt;either proxy access set up for the RJE &amp;gt;server or set up proper access control for &amp;gt;the directories (where the streams are &amp;gt;assigned to).&lt;BR /&gt;sys$sysdevice:[mailbox] is set (w:rwed).  Did have a thought - the RJE work files are in the users directory - it would cause an issue if there was an attempt to access those with the default FAL account - migh this be the problem?  Any way to specify where rje places the work files?</description>
      <pubDate>Mon, 14 Nov 2005 09:13:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670066#M50659</guid>
      <dc:creator>David Kramer_2</dc:creator>
      <dc:date>2005-11-14T09:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670067#M50660</link>
      <description>Hi David,&lt;BR /&gt;&lt;BR /&gt;According to the user guide, only files with the following attributes can be transmitted to an IBM system on a workstation reader stream:&lt;BR /&gt;&lt;BR /&gt;File organisation Sequential&lt;BR /&gt;Record format Fixed, stream CR, or variable&lt;BR /&gt;File protection World:R&lt;BR /&gt;&lt;BR /&gt;The following is the reasoning.&lt;BR /&gt;&lt;BR /&gt;When we submit a job using SNASUBMIT, the actual data handling is done by the RJE server. It reads the submited JCL file via DECnet or TCP/IP and then transmit the file to the IBM host.&lt;BR /&gt;&lt;BR /&gt;When RJE server reads the submited JCL using DECnet, the FAL object (or session control application in Phase V terms) will be used. As you know, the default user for FAL only has NETMBX and TMPMBX privileges, it can only read files that has protection set to World:R.&lt;BR /&gt;&lt;BR /&gt;So make sure that you have all your JCL files set to world readable.&lt;BR /&gt;&lt;BR /&gt;Understanding the above, you can actually by-pass the setting of JCL files to world readable. The RJE server should be running under the system account, so you can add the following proxy in order to solve the file protection problem.&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; add/proxy 0::system system/default&lt;BR /&gt;&lt;BR /&gt;Hope the above helps.&lt;BR /&gt;&lt;BR /&gt;Thanks and regards.&lt;BR /&gt;&lt;BR /&gt;Michael&lt;BR /&gt;</description>
      <pubDate>Mon, 14 Nov 2005 20:59:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670067#M50660</guid>
      <dc:creator>Michael Yu_3</dc:creator>
      <dc:date>2005-11-14T20:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670068#M50661</link>
      <description>David, Michael:&lt;BR /&gt;&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;Understanding the above, you can actually by-pass the setting of JCL files to world readable. The RJE server should be running under the system account, so you can add the following proxy in order to solve the file protection problem.&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; add/proxy 0::system system/default&lt;BR /&gt;&lt;/QUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;I most strongly must advise against that!!&lt;BR /&gt;&lt;BR /&gt;After this, ANYbody can do ANYthing to your system! And without an identifiable trave WHO did it.&lt;BR /&gt;&lt;BR /&gt;If there are any objections to setting World:Read access (which I understood does not apply to you, but for completeness:) you may also make an ACL for the directory, which gives read access to only your FAL account.&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Nov 2005 05:29:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670068#M50661</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2005-11-15T05:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: SNA RJE</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670069#M50662</link>
      <description>Hi Jan,&lt;BR /&gt;&lt;BR /&gt;Please note the proxy is for 0::system which is the system account on the local node. I cannot see anyone else can use that proxy except the local system account.&lt;BR /&gt;&lt;BR /&gt;Thanks and regards.&lt;BR /&gt;&lt;BR /&gt;Michael&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 15 Nov 2005 05:37:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/sna-rje/m-p/3670069#M50662</guid>
      <dc:creator>Michael Yu_3</dc:creator>
      <dc:date>2005-11-15T05:37:52Z</dc:date>
    </item>
  </channel>
</rss>

