eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
IMVSECURFeature RACF eTrust CA-Top SecretResourceprotection(cont’d)AccessauthorizationsCICS transientdata destinationsCICS temporarystorage definitionsInstallation-defined resources (CDT)PERMIT commandCICS destinations (DCT)CICS temporary storage (TST)Installation-defined resources (RDT)TSS PERMIT commandUACCTSS PERMITs in the ALL RecordUser Privileges SPECIAL MSCA and SCA with administrativeauthoritiesAUDITOROPERATIONSCLAUTHGRPACCNODSNCHK, NOVLCHK, and NORESCHKattributesSCA with MISC1, RES(REPORT) andDATA(ALL) authoritiesAdministrator with specifically namedresource XAUTH authorityPROFILEsAdministration RACF commands TSS commandsReports andListingsISPF panelsRACF ReportWriterDSMON UtilitySETROPS ListOutputLISTUSER OutputPanels for different facilities (TSO,CA-Roscoe, CICS and IMS)TSSUTIL, TSSTRACKTSSAUDIT, TSS LIST, TSS WHOHAS andTSS WHOOWNSTSS LISTTSS LISTCustomization Exits Exists and interfacesOther featuresUserididentificationLoggingStarted TasksACID identificationLoggingSTC facilityB–2 Security Cookbook
ADDGRPADDGRPThe ADDGRP command is used to add a group definition. For example:ADDGRP OMVSGRP OMVS(GID(1))In eTrust CA-Top Secret, this would be a profile record as follows:TSS ADD(OMVSGRP) GID(1)ADDUSERRACF uses the ADDUSER command to define a new user to its database and todefine the profile information necessary to allow that user to use the desiredcomponents of the system. eTrust CA-Top Secret does the same using ACID andPROFILE records. The ADDUSER command is the same as the ADD commandin eTrust CA-Top Secret. For example:ADDUSER USER01 DFLTGRP(OMVSGRP) OMVS(UID(200) HOME(/) PROGRAM(/bin/sh))PASSWORD(password)In eTrust CA-Top Secret, this would be rendered as follows:TSS CREATE(USER01) TYPE(USER) DEPARTMENT(dept1) PASSWORD(password,0)TSS ADDTO(USER01) GROUP(OMVSGRP) UID(0) HOME(/) PROGRAM(/bin/sh)ALTUSERRACF uses the ALTUSER command to change an existing user’s profile. Forexample:ALTUSER USER01 CICS(OPCLASS(10) OPIDENT(U01) TIMEOUT(30))In eTrust CA-Top Secret, this would be a change to the Acid record as follows:TSS ADD(USER01) OPCLASS(10) OPID(U01) OPTIME(30)CLASSIn RACF, with the exception of DATASET, USER, and GROUP classes, theentries in the class descriptor table (CDT) represent all resource classes both forMVS and VM. The CDT consists of two modules: one is for IBM-supplied entries,the other is for installation-defined entries.RACF to eTrust CA-Top Secret Translation B–3
- Page 107 and 108: z/OS and OS/390 Security Server Sup
- Page 109 and 110: z/OS and OS/390 Security Server Sup
- Page 111 and 112: Chapter2Controlling Access to theHi
- Page 113 and 114: Controlling HFS Using the Native UN
- Page 115 and 116: Controlling HFS Using CA SAF HFS Se
- Page 117 and 118: Securing HFS FunctionsKeywordALLCON
- Page 119 and 120: Securing HFS FunctionsFile Function
- Page 121 and 122: Implementing CA SAF HFS SecurityImp
- Page 123 and 124: HFSSEC Control Option+12—The addr
- Page 125 and 126: HFSSEC Control OptionDiagnosticsThe
- Page 127 and 128: HFSSEC Control OptionUNIX CMDCHMOD(
- Page 129 and 130: HFSSEC Control OptionTSSSUTIL EQUIV
- Page 131 and 132: HFSSEC Control OptionUNIX CMDS ACCE
- Page 133 and 134: HFSSEC Control OptionExample 1// JO
- Page 135 and 136: HFSSEC Control OptionExample 2// JO
- Page 137 and 138: MessagesMessagesCAS2301EEVENT PROCE
- Page 139 and 140: MessagesCAS2306Wxxxxxxxxxxxxxxx EVE
- Page 141: MessagesCAS2319ITRACEID=aaaaaaaa US
- Page 144 and 145: The SYSPLEX XES FunctionThere are t
- Page 146 and 147: eTrust CA-Top Secret and the SYSPLE
- Page 148 and 149: Defining the Sysplex to eTrust CA-T
- Page 150 and 151: Managing the Coupling FacilityWhen
- Page 152 and 153: Defining SYSTEM LOGGER to eTrust CA
- Page 154 and 155: IMVSECUR/*=========================
- Page 156 and 157: IMVSECUR/*=========================
- Page 160 and 161: PERMITIn eTrust CA-Top Secret, all
- Page 163 and 164: Indexcomponent names for z/OS and O
- Page 165 and 166: OpenEdition MVS supportACIDs needed
ADDGRPADDGRPThe ADDGRP comm<strong>and</strong> is used to add a group definition. For example:ADDGRP OMVSGRP OMVS(GID(1))In <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, this would be a profile record as follows:TSS ADD(OMVSGRP) GID(1)ADDUSERRACF uses the ADDUSER comm<strong>and</strong> to define a new user to its database <strong>and</strong> todefine the profile in<strong>for</strong>mation necessary to allow that user to use the desiredcomponents of the system. <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> does the same using ACID <strong>and</strong>PROFILE records. The ADDUSER comm<strong>and</strong> is the same as the ADD comm<strong>and</strong>in <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>. For example:ADDUSER USER01 DFLTGRP(OMVSGRP) OMVS(UID(200) HOME(/) PROGRAM(/bin/sh))PASSWORD(password)In <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, this would be rendered as follows:TSS CREATE(USER01) TYPE(USER) DEPARTMENT(dept1) PASSWORD(password,0)TSS ADDTO(USER01) GROUP(OMVSGRP) UID(0) HOME(/) PROGRAM(/bin/sh)ALTUSERRACF uses the ALTUSER comm<strong>and</strong> to change an existing user’s profile. Forexample:ALTUSER USER01 CICS(OPCLASS(10) OPIDENT(U01) TIMEOUT(30))In <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, this would be a change to the Acid record as follows:TSS ADD(USER01) OPCLASS(10) OPID(U01) OPTIME(30)CLASSIn RACF, with the exception of DATASET, USER, <strong>and</strong> GROUP classes, theentries in the class descriptor table (CDT) represent all resource classes both <strong>for</strong>MVS <strong>and</strong> VM. The CDT consists of two modules: one is <strong>for</strong> IBM-supplied entries,the other is <strong>for</strong> installation-defined entries.RACF to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> Translation B–3