12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

HFSSEC Control OptionThe exit can use this exit function to make any specific modifications to the pathname beyond that already per<strong>for</strong>med by <strong>CA</strong> SAF HFS security processing.TroubleshootingThe following section discusses troubleshooting solutions.ReportingReporting is done through the existing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> resource report,TSSUTIL. When the AUDIT attribute is on the user’s acid or specificpermissions, audit records can also appear on the report if they are requested inthe report criteria. The report will show the translated name of the HFS file used<strong>for</strong> validation. TSSUTIL should be reviewed when researching validationproblems.In addition, the online real-time monitor TSSTRACK can also be used to monitorHFS file security related events.OPTIONS(32)Control option, OPTIONS(32), provides support <strong>for</strong> USS event logging to the AuditTracking File.To take advantage of this feature, the LONG option must be specified inTSSUTIL. This will ensure that the full 256-character resource name can bedisplayed. Logging will only take place <strong>for</strong> the acids that have the AUDIT orTRACE attributes assigned.A new RDT class called USSLOG is introduced with this new USSLOG feature.This will allow TSSUTIL to select USSLOG records with the RESCLASS(USSLOG) option <strong>and</strong> to report the access level <strong>for</strong> the USS event. All of therecords are displayed as a resource type of USSLOG.The resource name field will display the USS function, i.e., INIT_USP <strong>and</strong> <strong>for</strong>some types of USS events, i.e., CHECK_ACCESS, the path name <strong>and</strong> file namebeing assessed. (In the example of the TSSUTIL report below, you can see howthe records are displayed)The TSSOERPT can still be used to get additional detailed in<strong>for</strong>mation about theUSS event, such as UID, GID or group name. Otherwise TSSUTIL will nowcontain the event in<strong>for</strong>mation such as: User ID’s, Modes, Function, Path Names,File Names, Return Code, Facility, etc. (See the example below to see how thetypical record are displayed). As part of <strong>CA</strong>SAF, USS events are being logged toSMF as well.2–14 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!