12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Distributed File Server SMB SUPPORTDistributed File Server SMB SUPPORTDistributed File Server (DFS) SMB support provides a server that makes the HFSfile available to SMB clients. Server Message Block (SMB) is a protocol <strong>for</strong> remotefile/print access used by Windows <strong>and</strong> <strong>OS</strong>/2 clients. The following steps mustbe taken to use this support:1. Define a facility <strong>for</strong> DFS in the TSS control file. Add the definition byrenaming a USERxx facility entry:FAC(USERXX=NAME=DFS)FAC(DFS=PGM=DFSCNTL)FAC(DFS=NOTSOC,RES,NOIJU,AUTHINIT)2. Create the region acid <strong>for</strong> DFS:TSS CRE(DFS) NAME(‘DFS REGION ACID’) FAC(BATCH,STC) PASS(XXXXXXXX)DEPT(XXXX) MASTFAC(DFS) NORESCHK NODSNCHK3. Define the DFS procedure to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>:TSS ADD(STC) PROCN(DFS procname) ACID(DFS)4. Define the DFSKERN procedure to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>:TSS ADD(STC) PROCN(DFS kern procname) ACID(DFS)SMB ENCRYPTED PASSWORD SUPPORTWith z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390, to have the SMB server use the encrypted passwordprocessing, you must add the entry DCE.PASSWORD.KEY to the SDTKEYSMSTR record. The syntax of the comm<strong>and</strong> is as follows:TSS ADD(SDT) KEYSMSTR(DCE.PASSWORD.KEY) DCENCRY(KKKKKKKK)KEYMASK | KEYNCRYKEYSMSTR—this attribute has only one value, which is DCE.PASSWORD.KEY,which must be entered in uppercase characters.DCENCRY—this value is a 16-character hexadecimal encryption keyKEYMASK—this value indicates that the DCENCRY key is used to mask theuser’s DCE password when it is stored in the DCEKEY field of the user’s acidrecord. KEYMASK is the defaultKEYENCRY—this value indicates that the DCENCRY key is used to encrypt theuser’s DCE password when it is stored in the user’s acid recordNote: Only the MS<strong>CA</strong> can specify the KEYSMSTR keyword.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–91

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!