TSO APPL name not being passed to MFA

Document ID : KB000100155
Last Modified Date : 05/06/2018
Show Technical Document Details
Question:
TSO VERIFYAPPL(ON) was set in IBM's MFA, but the APPL is not being passed.  How does that work with ACF2?
Answer:
The ACF2 TSO interface will use the APPL in the GSO TSO TSOGNAME field if it's filled in. This will work for the MFABYPASS rules. 

But, there is a catch. TSOGNAME is also used as the APPL when a user logs onto TSO with a passticket. So if you use passtickets at TSO signon, make sure those still work. You could always set the TSOGNAME to TSO followed by the LPAR sysid - this is what passtickets will use when TSOGNAME is not filled in. 

Example: if your LPAR sysid is TPCQ then set TSOGNAME(TSOTPCQ) and make a rule for MFABYPASS.APPL.TSOTPCQ. This way, it should work for both MFA and for passtickets.