R_usermap() Can Get SAF_RC=8 RACF_RC=8 RACF_REAS=8 With Kerberos.

Document ID : KB000010312
Last Modified Date : 14/02/2018
Show Technical Document Details
Introduction:

 

- SSH with Kerberos could get the below error: 

SAFRC=8 RACFRC=8 and RACFREAS=8 FOTS3833 ssh_gssapi_krb5_userok:

R_usermap(): SAF_RC=8 RACF_RC=8 RACF_REAS=8 krb5 principal: "xxxx@CA.COM

Environment:
z/OS
Instructions:

 

 

- The Kerberos principal was not associated to the userid. After it's defined, the authentication checking is passed.

Additional Information:

 

- If you want to have more information about CA Top Secret and Kerberos go to link:

 

https://docops.ca.com/ca-top-secret-for-z-os/16-0/en/search?q=kerberos&max=10&key=CTSFZ16