12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IMVSECUR/*=====================================================================*//* <strong>OS</strong>/390 Firewall setup. *//*=====================================================================*/TSS CRE(FWGRP) TYPE(GROUP) NAME('FIREWALL GROUP') DEPT(anydept)TSS ADD(FWGRP) GID(nn) any unused GID number is allowed/* */TSS CRE(FWKERN) TYPE(USER) NAME('FIREWALL STARTUP ID') -DEPT(anydept) FAC(STC,BATCH) PASS(password,0)TSS ADD(FWKERN) GROUP(FWGRP) DFLTGRP(FWGRP) -HOME(/usr/lpp/fw/home/fwkern/) OMVSPGM(/bin/sh) UID(0)TSS ADD(STC) PROCNAME(FWKERN) ACID(FWKERN)SS MODIFY(OMVSTABS)/* */TSS ADD(STC) PROCNAME(I<strong>CA</strong>PSLOG) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PSOCK) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PPFTP) ACID(FWKERN)TSS ADD(STC) PROCNAME(I<strong>CA</strong>PTNAT) ACID(FWKERN)/*TSS ADDTO(anydept) DSN(TCPIP.)TSS PERMIT(FWKERN) DSN(TCPIP.) ACCESS(READ)/* */TSS PERMIT(FWKERN) IBMFAC(BPX.SMF) ACCESS(READ)/* *//* To give administrators access to FWGRP *//* */TSS ADDTO(acid) GROUP(FWGRP)/* *//* *//* Define <strong>and</strong> give ICFS services */TSS ADDTO(anydept) CSFSERV(service-name)TSS PERMIT(acid) CSFSERV(service-name) ACCESS(READ)/* *//*======================================================================*//* LDAP setup. *//*=====================================================================*/TSS CRE(LDAPGRP) TYPE(GROUP) NAME('LDAP GROUP') DEPT(anydept)TSS ADD(LDAPGRP) GID(nn) any unused GID number is allowed/* */TSS CRE(LDAPSRV) TYPE(USER) NAME('LDAP STARTUP ID') -DEPT(anydept) FAC(STC,BATCH) PASS(password,0)TSS ADD(LDAPSRV) GROUP(LDAPGRP) DFLTGRP(LDAPGRP) -HOME(/) OMVSPGM(/bin/sh) UID(0)TSS ADD(STC) PROCNAME(LDAPSRV) ACID(LDAPSRV)TSS MODIFY(OMVSTABS)/* */TSS PERMIT(LDAPSRV) IBMFAC(BPX.DAEMON) ACCESS(READ)TSS PERMIT(LDAPSRV) IBMFAC(BPX.SERVER) ACCESS(UPDATE)/* *//* To give administrators access to LDAPGRP */TSS ADDTO(acid) GROUP(LDAPGRP)/*A–4 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!