12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using FTP2. The FTP server acid requires the ability to per<strong>for</strong>m work on behalf of userslogging on to FTP, <strong>and</strong> at times switch its identity to that of a user.Accordingly, it requires superuser authority. This can be done as shownabove, by adding UID(0) to the acid. Alternatively, you can give the acid anon-zero UID <strong>and</strong> permit it access to Superuser authority as follows:TSS PERMIT(FTPD) IBMFAC(BPX.SUPERUSER) ACCESS(READ)IBM recommends that you increase your level of security by protectingdaemon authority. This is accomplished in <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> by owningthe resource IBMFAC(BPX.DAEM). Once this is done, you must explicitlypermit daemon authority to the server, even if it is running under UID(0), byentering the following comm<strong>and</strong>:TSS PERMIT(FTPD) IBMFAC(BPX.DAEMON) ACCESS(READ)3. The TSS Facility named "TCP" is used to control which end users are able toaccess OE/FTP. Access to the "TCP" Facility must be given to user acids thataccess OE/FTP.Considerations <strong>for</strong> Securing FTPUsers accessing FTP must log on to the service be<strong>for</strong>e using it. This requires themto supply their userids <strong>and</strong> passwords <strong>and</strong> <strong>for</strong> their userids to have access to theTCPIP facility. FTP also supports anonymous logons.In the FTPDATA configuration file, the parameter ANONYMOUS controlswhether this feature can be used. The parameter can be specified in one of threeways:ANONYMOUSANONYMOUS useridANONYMOUS userid/passwordIf the parameter is specified without a following userid, <strong>and</strong> an FTP userspecifies anonymous at logon time, RACINIT are issued <strong>for</strong> the acidANONYMOU. If this acid is defined to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> <strong>and</strong> has access tothe TCP/IP facility, the user is allowed to log on <strong>and</strong> run under the authority ofthe "ANONYMOU" acid.If the parameter is specified with a following userid, the user must provide thecorrect password <strong>for</strong> this userid. If the parameter is specified with both USERID<strong>and</strong> PASSWORD, these values are used to sign on the user.The use of ANONYMOUS logon should be carefully considered, <strong>and</strong> if used, canbe a c<strong>and</strong>idate <strong>for</strong> auditing.1–34 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!