12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390 <strong>Security</strong> Server Support4. Define additional started tasks used by the firewall daemons:TSS ADD(STC) PROCNAME(I<strong>CA</strong>PSLOG) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PSOCK) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PPFTP) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PFLOG) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PTNAT) ACID(FWKERN)5. Permit FWKERN access to READ the TCP/IP data sets:TSS PERMIT(FWKERN) DSN(TCPIP.*) ACCESS(READ)The high level qualifier of these data sets might have been renamed from“TCPIP” when installed on your system.6. Permit the FWKERN acid to the SMF logging facility:TSS PERMIT(FWKERN) IBMFAC(BPX.SMF) ACCESS(READ)7. Permit the PFTP server to the BPX.DAEMON facility:TSS PERMIT(FWKERN) IBMFAC(BPX.DAEMON) ACCESS(READ)8. Adding Firewall Administrators to FWGRP:Firewall administrators must be members of the group FWGRP or havesuperuser authority. The following comm<strong>and</strong> gives an administrator thefirewall group:TSS ADD(administrator) GROUP(FWGRP)9. Firewall Technologies has the ability to invoke z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390 IntegratedCryptographic facilities to per<strong>for</strong>m internal security functions. These servicesare protected using the resource class CSFSERV. Users must be permitted tothe individual services necessary. This is accomplished using the followingcomm<strong>and</strong>s:TSS ADD(dept) CSFSERV(service-name)TSS PERMIT(acid) CSFSERV(service-name) ACCESS(READ)The individual service-names are documented in the appropriate IBMFirewall manuals <strong>and</strong> the ICSF/MVS Administrators Guide.LDAP ServerIBM provides a Lightweight Directory Access Protocol (LDAP) Server with z/<strong>OS</strong><strong>and</strong> <strong>OS</strong>/390 releases 2.5 <strong>and</strong> above. This server can be used to store directoryin<strong>for</strong>mation, such as email accounts. The LDAP server uses a DB2-based file tostore directory in<strong>for</strong>mation.1–98 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!