Knowledge Base

Enabling an APPC/CPIC Program to Use Persistent Verification

Article ID: 198179

Article Last Modified on 3/8/2005


APPLIES TO


This article was previously published under Q198179

SUMMARY

Microsoft SNA Server 3.0 Service Pack 3 and later versions include support for LU6.2 "persistent verification" as described in the following Knowledge Base article:

180866 Persistent Verification Support for APPC Sessions

In order for an application to make use of SNA Server persistent verification support, the application must do the following:

MORE INFORMATION

Persistent verification (PV) eliminates the need to provide a user ID and password on each Attach during multiple conversations between a user and its partner at a remote LU. The user is verified once during a sign-on process during its initial conversation over an LU6.2 session between an LU/LU pair, and remains verified until the user is signed off by the remote LU, or if all sessions between the LUs are ended.

In order for persistent verification to be used, the host system must indicate support within its BIND command or response, by setting the following option:

Byte 23, Bit 7 persistent verification capability must be set to 1 (ON): (Persistent Verification indicator is supported on incoming FMH-5s)

Note that SNA Server does not set this bit, because SNA Server only supports the sending of FMH-5 Attach requests with persistent verification. SNA Server does not support incoming FMH-5 Attaches which have persistent verification set.

If SNA Server detects that the remote system supports persistent verification (as indicated in the host BIND message), then the APPC or CPIC application can take advantage of persistent verification by setting security = SAME, and by providing a user ID AND password on every allocate request. SNA Server then implements PV by maintaining a PV sign-on user list associated with each Remote APPC LU as follows: As mentioned above, SNA Server removes a user from its PV sign-on list when one of the following conditions occurs: There is no way to view the SNA Server PV sign-on list, although this is under consideration for a future release of SNA Server.

REFERENCES

IBM documents the format of the SNA BIND command and FMH-5 Attach requests in the following IBM reference:

Title: Systems Network Architecture Formats
IBM Document Number GA27-3136-14

For more information about persistent verification, please see the following IBM reference:

Title: SNA LU 6.2 Peer Protocols
IBM Document Number: SC31-6808-02

Keywords: kbinfo KB198179