12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

OpenEdition MVS / UNIX System Services SupportStep 2—Assign a GID (groupid) to the GROUP acids you created in Step 1.(Every group must have a GID number assigned to it.) A GID can be any numberfrom 0 to 2,147,483,647. Define a GID of 1 <strong>for</strong> the OMVSGRP group <strong>and</strong> a GID of2 <strong>for</strong> the TTY group by issuing the following TSS comm<strong>and</strong>:TSS ADD(OMVSGRP) GID(1)TSS ADD(TTY) GID(2)Step 3—You can now create the acid to be used <strong>for</strong> the OMVS started task.TSS CREATE(OMVSKERN) TYPE(USER) NAME('OMVS STC ACID') PASS(password,0)DEPT(dept) FACILITY(STC,APPC)FACILITY(APPC) is not required with <strong>OS</strong>/390 V2R4 <strong>and</strong> above.Step 4—Assign the acid to UNIX System Services MVS in the STC record.TSS ADD(STC) PROCNAME(OMVS) ACID(OMVSKERN)This example shows an acid created <strong>for</strong> OMVS as a started task.Step 5—Assign a UID to the STC acid created in Step 3. You must define theUNIX System Services MVS kernel started task acid as a superuser by assigningit a UID of 0.TSS ADD(OMVSKERN) UID(0)In accordance with UNIX System Services MVS requirements, giving an acid aUID of zero automatically designates her as a superuser.Step 6—Assign a default group to the STC acid.TSS ADD(OMVSKERN) DFLTGRP(OMVSGRP)Step 7—Assign the OMVSGRP <strong>and</strong> TTY groups to the OMVS acid by issuing thefollowing TSS comm<strong>and</strong>s:TSS ADD(OMVSKERN) GROUP(OMVSGRP)TSS ADD(OMVSKERN) GROUP(TTY)Step 8—Create the BPXROOT acid. The BPXPRMxx parameter SUPERUSER(xxxxxxx) identifies the userid to be used when a user issues 'SU' to change theirUID to 0. SU uses the function setuid() to accomplish this task. If theSUPERUSER(xxxxxxx) parameter is not specified in BPXPRMxx the useriddefaults to BPXROOT. This acid must be defined with a UID(0) <strong>and</strong> must nothave BPX.DAEMON authorization. Create this acid by issuing these comm<strong>and</strong>s:TSS CREATE(BPXROOT) TYPE(USER) NAME('BPXROOT ACID')PASS(password,0)DEPT(OMVSDEPT) FACILITY(APPC)TSS ADD(BPXROOT) GROUP(OMVSGRP) DFLTGRP(OMVSGRP) UID(0)FACILITY(APPC) is not required with <strong>OS</strong>/390 V2R4 <strong>and</strong> above.Step 9—Refresh the UID <strong>and</strong> GID tables.The following comm<strong>and</strong> will refresh these tables.TSS MODIFY(OMVSTABS)1–14 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!