12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OpenEdition MVS / UNIX System Services SupportNow that the UNIX System Services kernel acid has been defined to <strong>eTrust</strong><strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>, you can start USS by issuing the st<strong>and</strong>ard operator comm<strong>and</strong> <strong>for</strong>started tasks. Starting with <strong>OS</strong>/390 V1R3, the OMVS kernel is part of BCP. Thest<strong>and</strong>ard MVS start <strong>and</strong> stop comm<strong>and</strong>s no longer apply.Defining Other OMVS Started Task ACIDsDefine acids <strong>for</strong> other OMVS started tasks by issuing the following comm<strong>and</strong>s:TSS CRE(INETD) TYPE(USER) NAME('OMVS INETD STC')DEPT(dept) FAC(STC) PASSWORD(password,0)TSS ADD(INETD) UID(0) GROUP(OMVSGRP) DFLTGRP(OMVSGRP)HOME(/) OMVSPGM(/bin/sh)TSS CRE(RMFGAT) TYPE(USER) NAME('OMVS RMFGAT')DEPT(dept) FAC(STC) PASSWORD(password,0)TSS ADD(RMFGAT) UID(0) GROUP(OMVSGRP) DFLTGRP(OMVSGRP)HOME(/) OMVSPGM(/bin/sh)TSS ADD(STC) PROCNAME(INETD) ACID(INETD)TSS ADD(STC) PROCNAME(RMFGAT) ACID(RMFGAT)TSS ADD(STC) PROCNAME(BPXOINIT) ACID(OMVSKERN)TSS ADD(STC) PROCNAME(BPXAS) ACID(OMVSKERN)TSO ISHELL SupportThe <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> TSSOPMAT file contains a replacement member <strong>for</strong>the IBM REXX exec BPXWIRAC. Copy TSSOPMAT(BPXWIRAC) to a partitioneddata set compatible with your TSO SYSEXEC data sets. Assure that this file isconcatenated ahead of the IBM supplied SYSEXEC data sets. Failure to do thisresults in a S0C1 ABEND when entering the ISHELL.How to Create the Superuser Administrator ACIDThe UNIX System Services Shell <strong>and</strong> Utilities installation process createsdirectories in the Hierarchical File System (HFS). To per<strong>for</strong>m the installationsteps, the user must have superuser authority.A superuser is a special User acid under UNIX System Services. The superuser isa trusted acid who can maintain the UNIX System Services system <strong>and</strong>administer security in the HFS. It is important to note that assigning superuserauthority to an acid doesn't give the user any authority within <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong><strong>Secret</strong>, only authority in UNIX System Services. A superuser's UID has a value ofzero.Use caution when assigning acids the superuser authority. A superuser passes allsecurity checks, meaning the superuser can access any UNIX file in the filesystem.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!