12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OpenEdition MVS / UNIX System Services SupportBPX.STOR.SWAP—To allow users to make address spaces nonswappable.BPX.FILEATTR.APF—To allow users to turn on the APF-authorized attribute <strong>for</strong>an HFS file.BPX.FILEATTR.PROGCTL—To allow users to turn on the program controlledattribute <strong>for</strong> an HFS file.TSS PER(acid) IBMFAC(BPX.SMF) ACC(READ)Password Assignment <strong>for</strong> UID(0) AcidsA potential security concern exists <strong>for</strong> all acids defined with NOPW <strong>and</strong> UID(0).In certain scenarios, unauthorized access can occur with these acids using Telnetor Rlogin. To eliminate this potential security concern, you should addpasswords to all UID(0) assigned acids.TSS REPL(acid) PASS(xxxx,0)Several of the created started task acid definitions described in this documentspecify a password. Started task acids with passwords will cause a passwordprompt at the console on startup. This prompting is optional <strong>and</strong> can be turnedoff using the following methods:■■Control option setting OPTIONS(4) eliminates the console password promptat startup <strong>for</strong> the password protected STC acids.The OPTIONS control option must be set via the <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>parameter file. It can not be set with a MODIFY comm<strong>and</strong>.ACIDs Needed to Install UNIX System ServicesDuring the installation of UNIX System Services, you must create an acid <strong>for</strong> theOMVS started task <strong>and</strong> define the installer’s acid (typically a SYSPROG) as asuperuser via a UID(0).Defining the OMVS Started Task ACIDsUNIX System Services must be assigned an acid be<strong>for</strong>e you can begin using<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in this environment. Follow the steps below to create theOMVS started task acid.Step 1—Create the GROUP acids to which the started task acid are attached byissuing the following TSS comm<strong>and</strong>s:TSS CREATE(OMVSGRP) TYPE(GROUP) NAME('OMVS GROUP') DEPT(OMVSDEPT)TSS CREATE(TTY) TYPE(GROUP) NAME('REQ OMVS TTY GROUP') DEPT(OMVSDEPT)USS requires that a group name "TTY" must also exist, <strong>and</strong> it must be connectedto the OMVS started task acid. See the UNIX System Services Planning Guide <strong>for</strong>an explanation of TTY.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–13

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!