eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
Tracing UNIX System Services (OMVS)The following sample JCL, or a user-written substitute for the job stream, can beused to run the TSSOERPT report.//TSSOERPT JOB 1,'UNIX SYSTEM SERVICES MVS RPT',MSGCLASS=A,TYPRUN=HOLD//*//REPORT EXEC PGM=TSSOERPT//SYSPRINT DD SYSOUT=*//SYSUDUMP DD SYSOUT=*//RECMAN1 DD DSN=SYS1.MAN1,DISP=SHR//SYSIN DD.The selection criteria used in generating UNIX System Services MVS reports arelisted below, with brief descriptions. All selection criteria are described in detailafter the listing.TITLE(string)—Specifies a character string added to other title information at thetop of the report. This character string can be up to 35 characters in length. If youdo not specify this parameter, the report generator uses the first 35 characters inthe PARM field of the EXEC statement. If this character string is longer than 35characters, the first 35 characters are used.LINECNT(linecount)—The LINECNT(linecount) parameter specifies thenumber of output lines to be printed on a page. To prevent splitting ofinformation, eTrust CA-Top Secret report generators that issue multiple linereports check to see whether a complete report item will fit on a page. Themaximum number of output lines per page is limited only by the physicalconstraints of the output media being used, or to 99,999 lines.SDATE(00000|yyddd)—Specifies the start date of the report in Julian dateformat. SMF records generated before the SDATE value are ignored. The default,00000, specifies all available records.EDATE(99365|yyddd)—Specifies the ending Julian date from which reportinformation is selected. When combined with the SDATE parameter, thisparameter creates a window for report content. The default, 99365, specifies upto the time the job is run.STIME(0000|hhmm)—Specifies the start time for the interval from which SMFrecords are selected. Specifies the time at which reporting on the selected SMFrecords is to begin. This time is based on a 24-hour clock. Any SMF recordsgenerated before this specified time of day are ignored. The selection of recordsbegins at the STIME specified for each date in the SDATE/EDATE range. Thedefault, 0000, specifies midnight.ETIME(2359|hhmm)—Specifies the end time for the interval from which SMFrecords are selected. Specifies the time at which reporting on the selected SMFrecords is to end. Any SMF records generated after this specified time of day areignored. The default, 2359, specifies one minute before midnight.UID(value)—Specifies the UNIX System Services MVS UserID for which youintend to collect security information. Acceptable numeric values range fromzero to 2,147,483,647. This field is not maskable.1–22 Cookbook
Tracing UNIX System Services (OMVS)GID(value)—Specifies the UNIX System Services MVS GroupID for which youintend to collect security information. Acceptable numeric values range fromzero to 2,147,483,647. This field is not maskable.USER(acid)—Specifies the acid for which you want UNIX System Services MVSsecurity information collected. This field is not maskable.GROUP(acid)—Specifies the group for which you want UNIX System ServicesMVS security information collected. This field is not maskable.SERVICE(service)—Specifies the name of the SAF callable service for which youwant security information collected.TSSOERPT Output DescriptionTSSOERPT formats and reports security events occurring in the UNIX SystemServices environment. The output is extracted from the System ManagementFacility (SMF) data sets.The following is a sample of the output of TSSOERPT with DETAIL specified inthe job. TSSOERPT shows the logging of security events in an UNIX SystemServices MVS environment:02/02/98 98.033 11.54.44 — OMVS LOGGING REPORT — PAGE 1SERVICE USERID GROUP UID GID SAF RC RSNDATE TIME JOBNAME SOURCE SYSID CPUINIT_USP STRTE01 OMVSGRP 0 2 0 0 002/02/98 98.033 11:52:50 STRTE01 XE14 XE14Home : /U/STRTE01CHECK_ACCESS STRTE01 OMVSGRP 0 2 0 0 002/02/98 98.033 11:52:51 STRTE01 XE14 XE14Requested Access: SearchFunction: chdirUser Type: Security Defined Local UserPathname: /U/STRTE01Filename: /ROOTVolume : SMS001 Owner: rwx Group: --- Other: ---File Identifier: 000107000000000003Owning UID: 0 Owning GID: 0User Audit Options : Read Failure Write Failure Exec/Search FailureAuditor Audit Options: Read Failure Write Failure Exec/Search FailureDELETE_USP STRTE01 OMVSGRP 0 0 0 0 002/02/98 98.033 11:52:52 STRTE01 XE14 XE14This sample output shows one log entry for a INIT_USP request, one entry for aCHECK_ACCESS request, and one entry for a DELETE_USP request.In this example, the services of INIT_USP and DELETE_USP result in two-linelog entries consisting of field information. The CHECK_ACCESS request resultsin log entries that consist of two lines plus additional lines of information aboutthe request. This happens because different information is logged for differenttypes of requests.Implementing eTrust CA-Top Secret in a z/OS or OS/390 Environment 1–23
- Page 1 and 2: eTrust CA-Top Secret ® Securityfo
- Page 3: Technical UpdatesMay 2003The follow
- Page 6 and 7: Superuser Granularity .............
- Page 8 and 9: WLM (Workload Management)..........
- Page 11 and 12: Chapter1Implementing eTrust CA-TopS
- Page 13 and 14: z/OS and OS/390 CompatibilityThe li
- Page 15 and 16: z/OS and OS/390 Release-Specific Se
- Page 17 and 18: OpenEdition MVS / UNIX System Servi
- Page 19 and 20: OpenEdition MVS / UNIX System Servi
- Page 21 and 22: OpenEdition MVS / UNIX System Servi
- Page 23 and 24: OpenEdition MVS / UNIX System Servi
- Page 25 and 26: OpenEdition MVS / UNIX System Servi
- Page 27 and 28: OpenEdition MVS / UNIX System Servi
- Page 29 and 30: OpenEdition MVS / UNIX System Servi
- Page 31: Tracing UNIX System Services (OMVS)
- Page 35 and 36: Tracing UNIX System Services (OMVS)
- Page 37 and 38: Tracing UNIX System Services (OMVS)
- Page 39 and 40: Using TCP/IPFILE AUDIT OPTIONS—Th
- Page 41 and 42: Using TCP/IPwheresysname is the nam
- Page 43 and 44: Using FTPHow to Secure FTPFTP runs
- Page 45 and 46: Using TELNETTerminal Source Restric
- Page 47 and 48: WebSphere Application Server for z/
- Page 49 and 50: WebSphere Application Server for z/
- Page 51 and 52: WebSphere Application Server for z/
- Page 53 and 54: WebSphere Application Server for z/
- Page 55 and 56: WebSphere Application Server for z/
- Page 57 and 58: Lotus Domino Go Webserver/* PERMITT
- Page 59 and 60: Lotus Domino Go WebserverTo disable
- Page 61 and 62: Lotus Notes and Novell Directory Se
- Page 63 and 64: Digital Certificate SupportGeneral
- Page 65 and 66: Digital Certificate SupportFOR|UNTI
- Page 67 and 68: Digital Certificate SupportDCDSN(re
- Page 69 and 70: Digital Certificate SupportNote: In
- Page 71 and 72: Digital Certificate SupportYou can
- Page 73 and 74: Digital Certificate SupportCase #2.
- Page 75 and 76: Digital Certificate SupportImportan
- Page 77 and 78: Digital Certificate SupportAdding a
- Page 79 and 80: Digital Certificate SupportReconnec
- Page 81 and 82: Digital Certificate SupportTSS LIST
Tracing UNIX System Services (OMVS)The following sample JCL, or a user-written substitute <strong>for</strong> the job stream, can beused to run the TSSOERPT report.//TSSOERPT JOB 1,'UNIX SYSTEM SERVICES MVS RPT',MSGCLASS=A,TYPRUN=HOLD//*//REPORT EXEC PGM=TSSOERPT//SYSPRINT DD SYSOUT=*//SYSUDUMP DD SYSOUT=*//RECMAN1 DD DSN=SYS1.MAN1,DISP=SHR//SYSIN DD.The selection criteria used in generating UNIX System Services MVS reports arelisted below, with brief descriptions. All selection criteria are described in detailafter the listing.TITLE(string)—Specifies a character string added to other title in<strong>for</strong>mation at thetop of the report. This character string can be up to 35 characters in length. If youdo not specify this parameter, the report generator uses the first 35 characters inthe PARM field of the EXEC statement. If this character string is longer than 35characters, the first 35 characters are used.LINECNT(linecount)—The LINECNT(linecount) parameter specifies thenumber of output lines to be printed on a page. To prevent splitting ofin<strong>for</strong>mation, <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> report generators that issue multiple linereports check to see whether a complete report item will fit on a page. Themaximum number of output lines per page is limited only by the physicalconstraints of the output media being used, or to 99,999 lines.SDATE(00000|yyddd)—Specifies the start date of the report in Julian date<strong>for</strong>mat. SMF records generated be<strong>for</strong>e the SDATE value are ignored. The default,00000, specifies all available records.EDATE(99365|yyddd)—Specifies the ending Julian date from which reportin<strong>for</strong>mation is selected. When combined with the SDATE parameter, thisparameter creates a window <strong>for</strong> report content. The default, 99365, specifies upto the time the job is run.STIME(0000|hhmm)—Specifies the start time <strong>for</strong> the interval from which SMFrecords are selected. Specifies the time at which reporting on the selected SMFrecords is to begin. This time is based on a 24-hour clock. Any SMF recordsgenerated be<strong>for</strong>e this specified time of day are ignored. The selection of recordsbegins at the STIME specified <strong>for</strong> each date in the SDATE/EDATE range. Thedefault, 0000, specifies midnight.ETIME(2359|hhmm)—Specifies the end time <strong>for</strong> the interval from which SMFrecords are selected. Specifies the time at which reporting on the selected SMFrecords is to end. Any SMF records generated after this specified time of day areignored. The default, 2359, specifies one minute be<strong>for</strong>e midnight.UID(value)—Specifies the UNIX System Services MVS UserID <strong>for</strong> which youintend to collect security in<strong>for</strong>mation. Acceptable numeric values range fromzero to 2,147,483,647. This field is not maskable.1–22 Cookbook