Skip to main content
Question

Region VSAM External Security Manager (ESM) Issue

  • July 16, 2026
  • 2 replies
  • 22 views

Bruce Cheatwood
Forum|alt.badge.img+2

Background

Currently, I have added and enabled a VSAM External Security Manager (ESM) to my Rocket Enterprise Server. I added the VSAM ESM to the security managers list at the ES Administration and Directory Server security domain levels. I can sign on using the users I manage at the ES Administration level through the VSAM ESM’s verification and authentication.

 

The Issue

Although I have added the same VSAM ESM I’m using at the ES Administration and Directory Server security domains to the region’s security facility configuration, I cannot start the region using any of the default users provided in the default VSAM ESM. In the region, I navigated to [General → Verify]. On the Verify page, I clicked the [Run] button and got some more insight. It seems it is successfully loading the ESM configuration “VSAM ESM”, but it has failed to initialize the SAF manager due to reason 16. The error message states, “Safmgr initialization failed, reason = 16”.

 

I can’t start the region using the VSAM ESM, but I can using the Default Security Configuration. I want to be able to run the region using a user’s credentials verified and authenticated by the VSAM ESM in the same way it works in the ES Administration and Directory Server security domains. When using the VSAM ESM, the region tries to start but fails to do so due to the inability to start the listeners.

 

Region Security Settings

Use Default Security Facility Configuration = false/unchecked

Verify against all Security Managers = false/unchecked

Allow unknown resources = true/checked

Allow Unknown Users = true/checked

Create audit events = true/checked

Use all groups = true/checked

Cache TTL = 0

Cache Limit = 0

Configuration Information = none

Security Managers in list = VSAM ESM (enabled)

Currently signed in on ES Administration and Directory Server using default VSAM ESM SYSAD user.

2 replies

Henry Szabranski

Hi Bruce

Please can you provide the product version, platform information, console.log, log.html, thanks.


Bruce Cheatwood
Forum|alt.badge.img+2

We are using Enterprise Server 10.0.259 for Windows with patches applied thru pu08_382967.  We are trying to tie the VSAM-ESM to logins from a hummingbird emulator.  Do we need to enable TLS on the TN3270 listener with a certificate and private key for this to work?  Thanks.