eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

supportconnectw.ca.com
from supportconnectw.ca.com More from this publisher
12.07.2015 Views

z/OS and OS/390 Product/Component Naming Conventionz/OS and OS/390 Product/Component Naming ConventionAs each release of an operating system is made generally available, IBM oftenchanges the name of the supplied components or products. The following tablesprovide a reference for these supported releases.ProductTCP/IPCommunications Server IP for OS/390SecureWay Communications Serverfor OS/390Operating System ReleaseOS/390 Version 2 Release 4 and BelowOS/390 Version 2 Release 5 and AboveOS/390 Version 2 Release 8 and AboveProductOpen Edition MVSUNIX System Services for OS/390Operating System ReleaseOS/390 Version 2 Release 5 and BelowOS/390 Version 2 Release 6 and AboveProductInternet Connection Security ServerOperating System ReleaseOS/390 Version 1 Release 3 and BelowLotus Domino Go Webserver OS/390 Version 2 Release 4 & 5SecureWay Application Server forOS/390OS/390 Version 2 Release 8 and AboveProductCICSCICS Transaction ServerOperating System ReleaseMVS 5.1 and BelowMVS/ESA 5.2 and Abovez/OS and OS/390 Release-Specific Security ConcernsSeveral z/OS and OS/390 release-specific eTrust CA-Top Secret securityrequirements exist. In addition to the following information, it is important thatyou review the informational solutions discussed in the Upgrade Solutionssection of this document. These solutions contain the latest z/OS and OS/390release-specific implementation procedures and a list of the latest recommendedeTrust CA-Top Secret maintenance.1–4 Cookbook

z/OS and OS/390 Release-Specific Security Concernsz/OS V1R1 and AboveTwo new resource classes have been introduced by the Websphere ApplicationServer as EJBROLE and GEJBROLE. These classes are used to control access tomethods within Enterprise Java Beans (EJB). eTrust CA-Top Secret now allowsresource names to be in mixed case to support the functioning of these resourceclasses.eTrust CA-Top Secret now supports two new SAF callable services, R_cacheservand R_proxyserv. R_cacheserv is used to request the storage or retrieval ofinformation from a cache. R_proxyserv is used to request the LDAP Server toretrieve information from a directory information tree (DIT).z/OS and OS/390 V2R10 and AboveeTrust CA-Top Secret fully supports the Network and Privacy AuthenticationServer, known as Kerberos. eTrust CA-Top Secret stores and administersinformation about realms and principals for network authentication in the SDTand in the security file.In addition, eTrust CA-Top Secret fully supports the SERVAUTH class. Withz/OS and OS/390 V2R10, TCP/IP uses the SERVAUTH class to protect variousTCP/IP resources from unauthorized access.OS/390 V2R9 and AboveOS/390 V2R9 introduces support for Digital Certificate keyring and filteringfunctionality. Contact eTrust CA-Top Secret Support to obtain the requiredmaintenance for the above new features.OS/390 V2R8 and AboveOS/390 V2R8 introduces support for a more granular approach to securingsuperuser authorities. eTrust CA-Top Secret can be used to grant limited (orselected) subsets of superuser privileges to specific users, rather than having togrant complete superuser authority.OS/390 V2R8 also introduces support for User Limits. With this support you cancontrol the amount of resources consumed by individual OS/390 UNIX users.The BPXPRMxx member of PARMLIB determines resource limits for OS/390UNIX users (global setting). eTrust CA-Top Secret can be used to store supporteduser limit settings for each acid.Implementing eTrust CA-Top Secret in a z/OS or OS/390 Environment 1–5

z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390 Product/Component Naming Conventionz/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390 Product/Component Naming ConventionAs each release of an operating system is made generally available, IBM oftenchanges the name of the supplied components or products. The following tablesprovide a reference <strong>for</strong> these supported releases.ProductTCP/IPCommunications Server IP <strong>for</strong> <strong>OS</strong>/390SecureWay Communications Server<strong>for</strong> <strong>OS</strong>/390Operating System Release<strong>OS</strong>/390 Version 2 Release 4 <strong>and</strong> Below<strong>OS</strong>/390 Version 2 Release 5 <strong>and</strong> Above<strong>OS</strong>/390 Version 2 Release 8 <strong>and</strong> AboveProductOpen Edition MVSUNIX System Services <strong>for</strong> <strong>OS</strong>/390Operating System Release<strong>OS</strong>/390 Version 2 Release 5 <strong>and</strong> Below<strong>OS</strong>/390 Version 2 Release 6 <strong>and</strong> AboveProductInternet Connection <strong>Security</strong> ServerOperating System Release<strong>OS</strong>/390 Version 1 Release 3 <strong>and</strong> BelowLotus Domino Go Webserver <strong>OS</strong>/390 Version 2 Release 4 & 5SecureWay Application Server <strong>for</strong><strong>OS</strong>/390<strong>OS</strong>/390 Version 2 Release 8 <strong>and</strong> AboveProductCICSCICS Transaction ServerOperating System ReleaseMVS 5.1 <strong>and</strong> BelowMVS/ESA 5.2 <strong>and</strong> Abovez/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390 Release-Specific <strong>Security</strong> ConcernsSeveral z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390 release-specific <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> securityrequirements exist. In addition to the following in<strong>for</strong>mation, it is important thatyou review the in<strong>for</strong>mational solutions discussed in the Upgrade Solutionssection of this document. These solutions contain the latest z/<strong>OS</strong> <strong>and</strong> <strong>OS</strong>/390release-specific implementation procedures <strong>and</strong> a list of the latest recommended<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> maintenance.1–4 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!