eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect
Tracing UNIX System Services (OMVS)EXEC_SET—Changes the effective and saved UID or GID or both.■■Set UID—Change made to UID.Set GID—Change made to GID.FORK_EXIT—Indicates that a call was made to get the security information for aforked process.GET_GMAP—Indicates that a call was made to determine the GID for agroupname or the groupname for a GID.GET_SUPPL_GROUP—Indicates that a call was made to determine whatgroups the current process or user belongs to.GET_UMAP—Indicates that a call was made to determine the UID for ausername or the username for a UID.GET_USERS_GROUPS—Indicates that a call was made to determine the groupsto which a specific userid belongs.INIT_USP—Indicates initial user access to UNIX System Services MVS.■■Home—The home directory of the user at initial access to UNIX SystemServices MVS.Program—The name of the program for the indicated user at initial access toUNIX System Services MVS.MAKE_FSP—Seen when a file or directory is created.■■File Type—The filetype of the file for which the FSP is being created. It tellswhether a file is a directory, a regular file or one of several special types offiles.File Permissions—The file access permissions to be assigned to the indicatedfile. These are displayed in the fields named Owner, Group, and Other.Values for the fields are r for READ, w for WRITE, x for EXECUTE, and s forSEARCH.MAKE_ROOT_FSP—Indicates that a new file system is being initialized in anew PDSE/x data set.PTRACE_AUTH_CHK—Indicates that a check was made to see if a callingprocess can ptrace a target process it is calling.QUERY_FILE_OPTS—Indicates that file security options were queried todetermine the settings.QUERY_SEC_OPTION—Indicates that system security options were queried todetermine the settings.1–26 Cookbook
Tracing UNIX System Services (OMVS)SET_EFFECTIV_GID—Changes the effective GID to a different GID.■■■■GID To Be Set—The GID which is to be set as the effective GID.Real GID—The actual GID of this user.Effective GID—The GID under which this user's accesses are beingvalidated.Saved GID—Internally used GID.SET_EFFECTIV_UID—Changes the effective UID to a different UID.■■■■UID To Be Set—The UID which is to be set as the effective UID.Real UID—The actual UID of this user.Effective UID—The UID under which this user's accesses are beingvalidated.Saved UID—Internally used UID.SET_FILE_MASK—Change of permissions that a program sets in a new file ordirectory when it creates a new file or directory.SET_GID—Change the real, effective and saved GIDs to a different GID.■■■■GID To Be Set—The GID, which is to be set as the current GID.Real GID—The actual GID of this user.Effective GID—The GID under which this user's accesses are beingvalidated.Saved GID—Internally used GID.SET_UID—Change the real, effective and saved UID to a different UID.■■■■UID To Be Set—The UID which is to be set as the current UID.Real UID—The actual UID of this user or process.Effective UID—The UID under which this user's accesses are beingvalidated.Saved UID—Internally used UID.SUMMARY—Specifies the report is to include a three-line entry for each eventlogged. Produces a three-line entry for each logged event.DETAIL—Specifies the report is to include all the information available for eachlogging event. Produces report entries that include all the information availablefor each logging event. The default is a detailed report.TITLE—'TITLE for TSSOERPT' specifies a character string added to other titleinformation at the top of the report.Implementing eTrust CA-Top Secret in a z/OS or OS/390 Environment 1–27
- Page 1 and 2: eTrust CA-Top Secret ® Securityfo
- Page 3: Technical UpdatesMay 2003The follow
- Page 6 and 7: Superuser Granularity .............
- Page 8 and 9: WLM (Workload Management)..........
- Page 11 and 12: Chapter1Implementing eTrust CA-TopS
- Page 13 and 14: z/OS and OS/390 CompatibilityThe li
- Page 15 and 16: z/OS and OS/390 Release-Specific Se
- Page 17 and 18: OpenEdition MVS / UNIX System Servi
- Page 19 and 20: OpenEdition MVS / UNIX System Servi
- Page 21 and 22: OpenEdition MVS / UNIX System Servi
- Page 23 and 24: OpenEdition MVS / UNIX System Servi
- Page 25 and 26: OpenEdition MVS / UNIX System Servi
- Page 27 and 28: OpenEdition MVS / UNIX System Servi
- Page 29 and 30: OpenEdition MVS / UNIX System Servi
- Page 31 and 32: Tracing UNIX System Services (OMVS)
- Page 33 and 34: Tracing UNIX System Services (OMVS)
- Page 35: Tracing UNIX System Services (OMVS)
- Page 39 and 40: Using TCP/IPFILE AUDIT OPTIONS—Th
- Page 41 and 42: Using TCP/IPwheresysname is the nam
- Page 43 and 44: Using FTPHow to Secure FTPFTP runs
- Page 45 and 46: Using TELNETTerminal Source Restric
- Page 47 and 48: WebSphere Application Server for z/
- Page 49 and 50: WebSphere Application Server for z/
- Page 51 and 52: WebSphere Application Server for z/
- Page 53 and 54: WebSphere Application Server for z/
- Page 55 and 56: WebSphere Application Server for z/
- Page 57 and 58: Lotus Domino Go Webserver/* PERMITT
- Page 59 and 60: Lotus Domino Go WebserverTo disable
- Page 61 and 62: Lotus Notes and Novell Directory Se
- Page 63 and 64: Digital Certificate SupportGeneral
- Page 65 and 66: Digital Certificate SupportFOR|UNTI
- Page 67 and 68: Digital Certificate SupportDCDSN(re
- Page 69 and 70: Digital Certificate SupportNote: In
- Page 71 and 72: Digital Certificate SupportYou can
- Page 73 and 74: Digital Certificate SupportCase #2.
- Page 75 and 76: Digital Certificate SupportImportan
- Page 77 and 78: Digital Certificate SupportAdding a
- Page 79 and 80: Digital Certificate SupportReconnec
- Page 81 and 82: Digital Certificate SupportTSS LIST
- Page 83 and 84: Certificate Name Filtering SupportT
- Page 85 and 86: Certificate Name Filtering SupportI
Tracing UNIX System Services (OMVS)EXEC_SET—Changes the effective <strong>and</strong> saved UID or GID or both.■■Set UID—Change made to UID.Set GID—Change made to GID.FORK_EXIT—Indicates that a call was made to get the security in<strong>for</strong>mation <strong>for</strong> a<strong>for</strong>ked process.GET_GMAP—Indicates that a call was made to determine the GID <strong>for</strong> agroupname or the groupname <strong>for</strong> a GID.GET_SUPPL_GROUP—Indicates that a call was made to determine whatgroups the current process or user belongs to.GET_UMAP—Indicates that a call was made to determine the UID <strong>for</strong> ausername or the username <strong>for</strong> a UID.GET_USERS_GROUPS—Indicates that a call was made to determine the groupsto which a specific userid belongs.INIT_USP—Indicates initial user access to UNIX System Services MVS.■■Home—The home directory of the user at initial access to UNIX SystemServices MVS.Program—The name of the program <strong>for</strong> the indicated user at initial access toUNIX System Services MVS.MAKE_FSP—Seen when a file or directory is created.■■File Type—The filetype of the file <strong>for</strong> which the FSP is being created. It tellswhether a file is a directory, a regular file or one of several special types offiles.File Permissions—The file access permissions to be assigned to the indicatedfile. These are displayed in the fields named Owner, Group, <strong>and</strong> Other.Values <strong>for</strong> the fields are r <strong>for</strong> READ, w <strong>for</strong> WRITE, x <strong>for</strong> EXECUTE, <strong>and</strong> s <strong>for</strong>SEARCH.MAKE_ROOT_FSP—Indicates that a new file system is being initialized in anew PDSE/x data set.PTRACE_AUTH_CHK—Indicates that a check was made to see if a callingprocess can ptrace a target process it is calling.QUERY_FILE_OPTS—Indicates that file security options were queried todetermine the settings.QUERY_SEC_OPTION—Indicates that system security options were queried todetermine the settings.1–26 Cookbook