11.07.2015 Views

eTrust™CA-ACF2® Security for z/OS and OS/390 ... - SupportConnect

eTrust™CA-ACF2® Security for z/OS and OS/390 ... - SupportConnect

eTrust™CA-ACF2® Security for z/OS and OS/390 ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• ACF NEWMOD Enhancements. In eTrust CA-ACF2 Release 6.5, theF ACF2,NEWMOD(SAF) can dynamically reload all of the reloadableSAF modules without an IPL.• ACCESS Subcomm<strong>and</strong>. The ACCESS subcomm<strong>and</strong> has beenenhanced to streamline per<strong>for</strong>mance <strong>and</strong> provide additional in<strong>for</strong>mation.An in-storage Logonid/UID cross-reference table eliminates Logoniddatabase I/O <strong>and</strong> the Logonid scoping restriction placed on comm<strong>and</strong>issuers. The new display <strong>for</strong>mat lists keys, Nextkeys, prefixes, matchingrulelines <strong>and</strong> associated Logonids.• ACL Support. z/<strong>OS</strong> 1.3 introduces support <strong>for</strong> Access Control Lists(ACL) <strong>for</strong> the HFS file system. ACL’s provide more granular control ofaccess to the HFS files <strong>and</strong> directories when using native HFS security.eTrust CA-ACF2 supports the new R_setfacl callable service request tocreate, modify, <strong>and</strong> delete ACL’s, <strong>and</strong> checks ACL’s when access to afile or directory is requested.• Message <strong>and</strong> Panel Changes. Release 6.5 provides support <strong>for</strong> thecorporate-wide rebr<strong>and</strong>ing ef<strong>for</strong>t of the product name fromCA-ACF2 <strong>for</strong> <strong>OS</strong>/<strong>390</strong> to eTrust CA-ACF2 <strong>Security</strong> <strong>for</strong> z/<strong>OS</strong> <strong>and</strong><strong>OS</strong>/<strong>390</strong>. This rebr<strong>and</strong>ing changed many administrative <strong>and</strong> reportpanels, help panels, clists, report headings, messages, <strong>and</strong> alldocumentation.• Started Task (STC) GSO Record. The new STC GSO record can beused to assign a Logonid <strong>and</strong> optional Groupid based on the started taskID. Use of masking allows a single STC record to pertain to multiplestarted tasks.Prior to Release 6.5, a started task (STC) was assigned a Logonid basedon the following:o The user could explicitly request a Logonid via the USER= JCLparameter, or eTrust CA-ACF2 would use a Logonid equal to theSTC procedure nameo The appropriate default STC Logonid would be used.With Release 6.5 <strong>and</strong> the new GSO STC record, this processing isslightly altered.An internal table called the STC table is built during eTrustCA-ACF2 initialization or during REFRESH processing from theappropriate GSO STC records that are defined. This table is then used aspart of the process of determining what Logonid to assign to a particularSTC. This process can be summarized as follows:o The user could explicitly request a Logonid via the USER= JCLparameter, or eTrust CA-ACF2 would use a Logonid equal to theSTC procedure name.February 2003eTrust CA-ACF2 <strong>Security</strong> <strong>for</strong> z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/<strong>390</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!