eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

supportconnectw.ca.com
from supportconnectw.ca.com More from this publisher
12.07.2015 Views

HFSSEC Control OptionCA SAF HFS EQUIVILENCY TABLEHFSSEC(OFF) vs. HFSSEC(ON)OS/390 2.8 and aboveUNIX CMDS ACCESS GIVEN HPFSEC(ON) HPFSEC(OFF)CHAUDITAllow a user tochange user auditflagsBPX.CAHFS.CHANGE.FILE.AUDITFLAGSCHANGE_AUDIT_OPTAllow a user tochange a formatof a fileBPX.CAHFS.CHANGE.FILE.FORMATCHECK_FILE_OWNERCHMOD(UID)Allows a user tochange UID filepermission bitBPX.CAHFS.CHANGE.FI.LE.MODEBPX.CAHFS.CHANGE.FILE.MODE.EUIDCHANGE_FILE_MODECHMOD(STICKYBIT)Allows a user tochange Sticky bitfile permissionBPX.CAHFS.CHANGE.FILE.MODEBPX.CAHFS.CHANGE.FILE.MODE.EUIDCHANGE_FILE_MODEBPX.CAHFS.CHANGE.FILE.MODE.STICKYCHMOD(GID)Allows a user tochange GID bitBPX.CAHFS.CHANGE.FILE.MODECHANGE_FILE_MODEBPX.CAHFS.CHANGE.FILE.MODE.EUIDBPX.CAHFS.CHANGE.FILE.MODE.EGIDEXTATTR(ChangeAttributes)Allow a user toturn on APFattribute for anyHFS fileBPX.CAHFS.CHANGE.FILE.ATTRIBUTESSUPERUSER.FILESYS.FILEEXTATTR(ProgramControlled Attribute)Allow users toturn on theprogramcontrolledattributeBPX.CAHFS.CHANGE.FILE.OWNERSUPERUSER.FILESYS.FILECHOWNAllows a user tochangeownership offilesBPX.CAHFS.CHANGE.FILE.OWNERCHANGE_OWNER_GROUP2–20 Cookbook

HFSSEC Control OptionUNIX CMDS ACCESS GIVEN HPFSEC(ON) HPFSEC(OFF)MOUNTAllows a user tomount filesystemsBPX.CAHFS.MOUNTSUPERUSER.FILE.MOUNTUNMOUNTAllows a user toUnmount filesystemsBPX.CAHFS.UNMOUNTSUPERUSER.FILE.MOUNTLINKAllows a user tocreate a link toany HFSdirectoryBPX.CAHFS.CREATE.LINKSUPERUSER.FILESYS.FILERENAMEAllows a user torename an HFSdirectoryNO BPX CALL. HFS TRACESHOWS ONE EVENT.RENAMESUPERUSER.FILESYS.FILEEDIT(OPEN)Allows a user towrite to any HFSfileNO BPX CALL. HFS TRACESHOWS TWO EVENTS:OPEN AND RENAMESUPERUSER.FILESYS.FILEEXTERNAL(LINK)Allows a user tocreate an externallink to any HFSdirectoryBPX.CAHFS.CREATE.EXTERNAL.LINKSUPERUSER.FILESYS.FILESYMBOLIC(LINK)Allows a user tocreate a symboliclink to any HFSdirectoryBPX.CAHFS.CREATE.SYMBOLIC.LINKSUPERUSER.FILESYS.FILECHGRPAllows a user tochange groupsetting for a fileBPX.CAHFS.CHANGE.FILE.GROUPCHANGE_OWNER_GROUPKILLAllows a user tosend signals to aprocessSUPERUSER.PROCESS.GETPSENTSUPERUSER.PROCESS.KILLSU(SWITCH USER)Allows a user toswitch to superuser statusBPX.SUPERUSERSET_EFFECTIVE_UIDControlling Access to the Hierarchical File System 2–21

HFSSEC Control Option<strong>CA</strong> SAF HFS EQUIVILENCY TABLEHFSSEC(OFF) vs. HFSSEC(ON)<strong>OS</strong>/390 2.8 <strong>and</strong> aboveUNIX CMDS ACCESS GIVEN HPFSEC(ON) HPFSEC(OFF)CHAUDITAllow a user tochange user auditflagsBPX.<strong>CA</strong>HFS.CHANGE.FILE.AUDITFLAGSCHANGE_AUDIT_OPTAllow a user tochange a <strong>for</strong>matof a fileBPX.<strong>CA</strong>HFS.CHANGE.FILE.FORMATCHECK_FILE_OWNERCHMOD(UID)Allows a user tochange UID filepermission bitBPX.<strong>CA</strong>HFS.CHANGE.FI.LE.MODEBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODE.EUIDCHANGE_FILE_MODECHMOD(STICKYBIT)Allows a user tochange Sticky bitfile permissionBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODEBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODE.EUIDCHANGE_FILE_MODEBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODE.STICKYCHMOD(GID)Allows a user tochange GID bitBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODECHANGE_FILE_MODEBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODE.EUIDBPX.<strong>CA</strong>HFS.CHANGE.FILE.MODE.EGIDEXTATTR(ChangeAttributes)Allow a user toturn on APFattribute <strong>for</strong> anyHFS fileBPX.<strong>CA</strong>HFS.CHANGE.FILE.ATTRIBUTESSUPERUSER.FILESYS.FILEEXTATTR(ProgramControlled Attribute)Allow users toturn on theprogramcontrolledattributeBPX.<strong>CA</strong>HFS.CHANGE.FILE.OWNERSUPERUSER.FILESYS.FILECHOWNAllows a user tochangeownership offilesBPX.<strong>CA</strong>HFS.CHANGE.FILE.OWNERCHANGE_OWNER_GROUP2–20 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!