eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
Managing the Coupling FacilityWhen a structure ALTER processing completes, each connected system is postedby the Computer Associates security Coupling Facility service (CASECCFS) toallow those systems to update the size and utilization counts for the connectedstructure.Note: To display information about the current Coupling Facility XES structure,use the TSS MODIFY(STATUS(SYSPLEX)) command. The following sysplexrelated data will appear in message TSS9661I:CURRENT STRUCTURE SIZE—Current allocated sizeMAX STRUCTURE SIZE—Maximum structure sizeNUMBER OF STRUCTURE ENTRIES—Current entry countMAX NUMBER OF STRUCTURE EXTRIES—Maximum possible entry countAn example of message TSS9661I follows:TSS9661I CA-Top Secret SYSPLEX StatusCF CONNECT NAME(XE11 ) XCF GROUP(TSSXCF )STRUCTURE NAME(SECURITY3 ) ACTIVATEDCURRENT STRUCTURE SIZE( 10240K)MAX STRUCTURE SIZE( 16128K)NUMBER OF STRUCTURE ENTRIES( 132)MAX NUMBER OF STRUCTURE ENTRIES( 1223)Rebuilding the Coupling Facility StructureAfter you have updated the CFRM policy with new structure attributes such asSIZE or INITSIZE, you can use the SETXCF OS/390 operator command torebuild the Coupling Facility structure characteristics based on the new CFRMpolicy changes. The rebuild is performed with minimum disruption to theconnected systems.Use the following command to initiate the rebuild process based on the newCFRM policy structure attributes, while connected systems remain connected tothe structure.SETXCF START,REBUILD,STRNAME=strnameDuring the rebuild process, the system defers any requests that are issued whilethe structure is unavailable. These requests are processed after the rebuildprocess has completed.3–8 Cookbook
Defining SYSTEM LOGGER to eTrust CA-Top SecretThe following requirements apply to the system-managed rebuild:■■■■Coupling facility has to be at CFLEVEL=8 or higher.The structure has at least two entries in the CFRM PREFLIST.All systems using the CFRM couple data set must be at OS/390 version 8 orhigher.The CFRM couple data set must be formatted with the ITEMNAME(SMREBLD) NUMBER(1) statement.Connecting to the StructureAt startup, or through a start command, eTrust CA-Top Secret attempts toconnect to the defined structures in the Coupling Facility. If successful, eTrustCA-Top Secret attempts to use the Coupling Facility for all I/O direct requestsbeing made for the defined file.Defining SYSTEM LOGGER to eTrust CA-Top SecretSystem logger is an OS/390 component that allows an application to log datafrom different systems across a sysplex. A system logger application can besupplied by:■■■IBM, for example the CICS log manager and the operations log stream(OPERLOG)Independent software vendorsYour installationA system logger application can merge the log data from systems across thesysplex into a log stream. A log stream is simply a collection of data in log blocksresiding in a coupling facility list structure, on DASD, or on both.Using the Sysplex Coupling Facility 3–9
- Page 99 and 100: Mapping of Foreign EnvironmentsMapp
- Page 101 and 102: Distributed File Server SMB SUPPORT
- Page 103 and 104: NFS (Network File System)The first
- Page 105 and 106: z/OS and OS/390 Security Server Sup
- Page 107 and 108: z/OS and OS/390 Security Server Sup
- Page 109 and 110: z/OS and OS/390 Security Server Sup
- Page 111 and 112: Chapter2Controlling Access to theHi
- Page 113 and 114: Controlling HFS Using the Native UN
- Page 115 and 116: Controlling HFS Using CA SAF HFS Se
- Page 117 and 118: Securing HFS FunctionsKeywordALLCON
- Page 119 and 120: Securing HFS FunctionsFile Function
- Page 121 and 122: Implementing CA SAF HFS SecurityImp
- Page 123 and 124: HFSSEC Control Option+12—The addr
- Page 125 and 126: HFSSEC Control OptionDiagnosticsThe
- Page 127 and 128: HFSSEC Control OptionUNIX CMDCHMOD(
- Page 129 and 130: HFSSEC Control OptionTSSSUTIL EQUIV
- Page 131 and 132: HFSSEC Control OptionUNIX CMDS ACCE
- Page 133 and 134: HFSSEC Control OptionExample 1// JO
- Page 135 and 136: HFSSEC Control OptionExample 2// JO
- Page 137 and 138: MessagesMessagesCAS2301EEVENT PROCE
- Page 139 and 140: MessagesCAS2306Wxxxxxxxxxxxxxxx EVE
- Page 141: MessagesCAS2319ITRACEID=aaaaaaaa US
- Page 144 and 145: The SYSPLEX XES FunctionThere are t
- Page 146 and 147: eTrust CA-Top Secret and the SYSPLE
- Page 148 and 149: Defining the Sysplex to eTrust CA-T
- Page 152 and 153: Defining SYSTEM LOGGER to eTrust CA
- Page 154 and 155: IMVSECUR/*=========================
- Page 156 and 157: IMVSECUR/*=========================
- Page 158 and 159: IMVSECURFeature RACF eTrust CA-Top
- Page 160 and 161: PERMITIn eTrust CA-Top Secret, all
- Page 163 and 164: Indexcomponent names for z/OS and O
- Page 165 and 166: OpenEdition MVS supportACIDs needed
Defining SYSTEM LOGGER to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>The following requirements apply to the system-managed rebuild:■■■■Coupling facility has to be at CFLEVEL=8 or higher.The structure has at least two entries in the CFRM PREFLIST.All systems using the CFRM couple data set must be at <strong>OS</strong>/390 version 8 orhigher.The CFRM couple data set must be <strong>for</strong>matted with the ITEMNAME(SMREBLD) NUMBER(1) statement.Connecting to the StructureAt startup, or through a start comm<strong>and</strong>, <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> attempts toconnect to the defined structures in the Coupling Facility. If successful, <strong>eTrust</strong><strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> attempts to use the Coupling Facility <strong>for</strong> all I/O direct requestsbeing made <strong>for</strong> the defined file.Defining SYSTEM LOGGER to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>System logger is an <strong>OS</strong>/390 component that allows an application to log datafrom different systems across a sysplex. A system logger application can besupplied by:■■■IBM, <strong>for</strong> example the CICS log manager <strong>and</strong> the operations log stream(OPERLOG)Independent software vendorsYour installationA system logger application can merge the log data from systems across thesysplex into a log stream. A log stream is simply a collection of data in log blocksresiding in a coupling facility list structure, on DASD, or on both.Using the Sysplex Coupling Facility 3–9