eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

supportconnectw.ca.com
from supportconnectw.ca.com More from this publisher
12.07.2015 Views

IMVSECUR/*=====================================================================*//* OS/390 Firewall setup. *//*=====================================================================*/TSS CRE(FWGRP) TYPE(GROUP) NAME('FIREWALL GROUP') DEPT(anydept)TSS ADD(FWGRP) GID(nn) any unused GID number is allowed/* */TSS CRE(FWKERN) TYPE(USER) NAME('FIREWALL STARTUP ID') -DEPT(anydept) FAC(STC,BATCH) PASS(password,0)TSS ADD(FWKERN) GROUP(FWGRP) DFLTGRP(FWGRP) -HOME(/usr/lpp/fw/home/fwkern/) OMVSPGM(/bin/sh) UID(0)TSS ADD(STC) PROCNAME(FWKERN) ACID(FWKERN)SS MODIFY(OMVSTABS)/* */TSS ADD(STC) PROCNAME(ICAPSLOG) ACID(FWKERN)TSS ADD(STC) PROCNAME(ICAPSOCK) ACID(FWKERN)TSS ADD(STC) PROCNAME(ICAPPFTP) ACID(FWKERN)TSS ADD(STC) PROCNAME(ICAPTNAT) ACID(FWKERN)/*TSS ADDTO(anydept) DSN(TCPIP.)TSS PERMIT(FWKERN) DSN(TCPIP.) ACCESS(READ)/* */TSS PERMIT(FWKERN) IBMFAC(BPX.SMF) ACCESS(READ)/* *//* To give administrators access to FWGRP *//* */TSS ADDTO(acid) GROUP(FWGRP)/* *//* *//* Define and give ICFS services */TSS ADDTO(anydept) CSFSERV(service-name)TSS PERMIT(acid) CSFSERV(service-name) ACCESS(READ)/* *//*======================================================================*//* LDAP setup. *//*=====================================================================*/TSS CRE(LDAPGRP) TYPE(GROUP) NAME('LDAP GROUP') DEPT(anydept)TSS ADD(LDAPGRP) GID(nn) any unused GID number is allowed/* */TSS CRE(LDAPSRV) TYPE(USER) NAME('LDAP STARTUP ID') -DEPT(anydept) FAC(STC,BATCH) PASS(password,0)TSS ADD(LDAPSRV) GROUP(LDAPGRP) DFLTGRP(LDAPGRP) -HOME(/) OMVSPGM(/bin/sh) UID(0)TSS ADD(STC) PROCNAME(LDAPSRV) ACID(LDAPSRV)TSS MODIFY(OMVSTABS)/* */TSS PERMIT(LDAPSRV) IBMFAC(BPX.DAEMON) ACCESS(READ)TSS PERMIT(LDAPSRV) IBMFAC(BPX.SERVER) ACCESS(UPDATE)/* *//* To give administrators access to LDAPGRP */TSS ADDTO(acid) GROUP(LDAPGRP)/*A–4 Cookbook

AppendixBRACF to eTrust CA-Top SecretTranslationMany applications and products describe the setup for external security in RACFterms. The purpose of this Appendix is to describe what the RACF terminologymeans so a eTrust CA-Top Secret administrator can take the information andcreate the necessary eTrust CA-Top Secret records to implement it.Use the following chart to check the corresponding eTrust CA-Top Secret feature.Feature RACF eTrust CA-Top SecretUsers/GroupsResourceProtectionSPECIAL GroupconceptData SetsDASD volumesTape volumesTerminalsLoad modules(programs)IMS applicationgroup names(AIMS)IMS transactions(TIMS and GIMS)IMS applicationsCICS PSBsCICS transactionsCICS filesCICS journalsCICS programsMSCA, LSCAs, Zones, Divisions,Departments, Profiles, ACIDsData Sets (DSN)DASD volumes (VOL)Tape volumes (VOL)Terminals (TERM, SOURCE)Programs (PROG)IMS applications (APPL)Transactions via Limited Command Facility(LCF) or protected resources (OTRAN)Facility checkingCICS PSBsTransactions via Limited Command Facility(LCF) or protected resources (OTRAN)CICS files (FCT)CICS journals (JCT)CICS programs (PPT)RACF to eTrust CA-Top Secret Translation B–1

AppendixBRACF to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>TranslationMany applications <strong>and</strong> products describe the setup <strong>for</strong> external security in RACFterms. The purpose of this Appendix is to describe what the RACF terminologymeans so a <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> administrator can take the in<strong>for</strong>mation <strong>and</strong>create the necessary <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> records to implement it.Use the following chart to check the corresponding <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> feature.Feature RACF <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>Users/GroupsResourceProtectionSPECIAL GroupconceptData SetsDASD volumesTape volumesTerminalsLoad modules(programs)IMS applicationgroup names(AIMS)IMS transactions(TIMS <strong>and</strong> GIMS)IMS applicationsCICS PSBsCICS transactionsCICS filesCICS journalsCICS programsMS<strong>CA</strong>, LS<strong>CA</strong>s, Zones, Divisions,Departments, Profiles, ACIDsData Sets (DSN)DASD volumes (VOL)Tape volumes (VOL)Terminals (TERM, SOURCE)Programs (PROG)IMS applications (APPL)Transactions via Limited Comm<strong>and</strong> Facility(LCF) or protected resources (OTRAN)Facility checkingCICS PSBsTransactions via Limited Comm<strong>and</strong> Facility(LCF) or protected resources (OTRAN)CICS files (FCT)CICS journals (JCT)CICS programs (PPT)RACF to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> Translation B–1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!