12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

OpenEdition MVS / UNIX System Services SupportIf the OMVSGRP control option is not specified, the DFLTGRP from theOMVSUSR acid are used. Thus, the second way to specify a default group is toadd the default group to the OMVSUSR acid:TSS ADD('acidname') DFLTGRP('grpacid')To prevent a user with no UID or group from using the default values, add theNOOMVSDF attribute to the user acid.TSS ADD(acid) NOOMVSDFIf you define the BPX.DEFAULT.USER profile, all users will have access to z/<strong>OS</strong>or <strong>OS</strong>/390 UNIX. To limit access, define an OMVS segment with no UID. Doingthis will prevent unauthorized users from using a UNIX service. If users musthave anonymous access (<strong>for</strong> FTP or other socket use) without using the shell,define the initial program <strong>for</strong> the default user as /bin/echo. This allows users tohave a default UID without using the shell.How to use the AutoUID/AutoGID Enhancement <strong>for</strong> <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>The auto-assignment of the UID/GID numbers <strong>for</strong> the ADD or REPLACEcomm<strong>and</strong> includes the following features:■■■User can define a default rangeUser can restrict the search <strong>for</strong> an open number by entering a specific rangeIf no number is assigned <strong>and</strong> no range is given, AutoUID/GID restricts thesearch by checking through the defined default range■ If no range is given <strong>and</strong> there is no default range, AutoUID/GID starts at 1<strong>and</strong> searches until an available UID/GID is found■Zeros are excluded in the range searchExamplesTSS ADD|REP(acid|Group Acid) UID|GID(?) RANGE(,)orTSS ADD|REP(acid|Group Acid) UID|GID(?)orTSS ADD|REP(acid|Group Acid) UID|GID(?) RANGE(300,400)GID—Group Identification Number. Used in OMVS.UID—User Identification Number. Used in OMVS.range—Specifies a low <strong>and</strong> high value to be searched through in order to assigna UID/GID. The range can be 1 up to 2,147,483,647.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!