12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PERMITIn <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, all resources <strong>for</strong> both VM <strong>and</strong> MVS are defined in theResource Descriptor Table (RDT). Resources are predefined by <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong><strong>Secret</strong> or dynamically defined by the particular installation.PERMITThe RACF PERMIT comm<strong>and</strong> allows access to resources. The PERMIT comm<strong>and</strong>also exists in <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>. Use the TSS PERMIT comm<strong>and</strong> function toallow designated users to access the indicated data sets in an unlimited or arestricted manner. Restrictions are indicated by incorporating the appropriatePERMIT parameter. For example, the following RACF PERMIT allows USER01to read data set SYS1.PARMLIB:PERMIT SYS1.PARMLIB CLASS(DATASET) ID(user01) ACCESS(READ)In <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, this would be a permit:TSS PERMIT(user01) DSNAME(SYS1.PARMLIB) ACCESS(READ)RDEFINERDEFINE is used to define resources to RACF.In <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, the Resource Descriptor Table is a special ACID that isused to define resource classes <strong>and</strong> their properties. The RDT containspredefined TSS resource classes, including resources used by other ComputerAssociates product interfaces. It also contains dynamically defined resourceclasses. To administer the contents of the RDT Record, the TSS administrator canspecify attributes, access levels, <strong>and</strong> default access levels using the TSS ADDcomm<strong>and</strong>. The following is an example of creating a User defined resource in<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> using the TSS ADD comm<strong>and</strong>:TSS ADD(RDT) RESCLASS(xx)RESCODE(nn)ACLST(ALL=FFFF,UPDATE=6000,READ=4000,CREATE=1000,NONE=0000) ATTR(LONG)B–4 <strong>Security</strong> Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!