12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Lotus Domino Go WebserverInstalling Domino Go Webserver on a <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>-secured SystemNote: Previously defined UNIX System Services <strong>and</strong> TCP/IP requirements musthave been completed be<strong>for</strong>e you attempt to install the Domino Go Webserver.The examples in the following steps reflect default procnames, typical groupnames, <strong>and</strong> typical GID value. Overall, these comm<strong>and</strong>s simply ensure that avalid OMVS UID <strong>and</strong> GID exist <strong>for</strong> each of the started tasks that access OMVS.1. A TSS FACILITY should be created <strong>for</strong> the web server. Once created, thisfacility can be added to each user acid that is allowed to log on to the webserver. Tailor the following comm<strong>and</strong> <strong>and</strong> then add it to the existing <strong>eTrust</strong><strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> startup control options:TSS MODIFY FAC(USERx=NAME=IMWEB)2. The Domino Go Webserver requires an acid <strong>for</strong> the web server started task<strong>and</strong> <strong>for</strong> a web administrator. Both of these acids must be connected to anOMVS Group ID <strong>for</strong> the web server. The following comm<strong>and</strong>s accomplishthis using the IBM default values.The web server started task, whose procname is IMWEBSRV, is also referredto by IBM as the web server daemon. Also, changing the ID of the webadministrator is recommended; however, this change must be coordinatedwith updates to the web server configuration file.TSS CRE(IMWEB) TYPE(GROUP) NAME('WEBSERVER GROUP') DEPT(anydept)TSS ADD(IMWEB) GID(205)TSS CRE(WEBADM) TYPE(USER) NAME('WEB ADMINISTRATOR')DEPT(anydept) FAC(IMWEB) PASSWORD(password,0)TSS ADD(WEBADM) UID(206) GROUP(IMWEB) DFLTGRP(IMWEB)HOME(/usr/lpp/internet) OMVSPGM(/bin/sh)TSS CRE(WEBSRV) TYPE(USER) NAME('WEBSERVER DAEMON/STC')DEPT(dept) FAC(STC,IMWEB)PASSWORD(password,0)TSS ADD(WEBSRV) UID(0) GROUP(IMWEB) DFLTGRP(IMWEB)HOME(/usr/lpp/internet) OMVSPGM(/bin/sh)MASTFAC(IMWEB)TSS ADD(STC) PROCNAME(IMWEBSRV) ACID(WEBSRV)3. Three other user acids, each having their own connected group, are requiredunless "surrogate user" support is disabled. This feature permits users toaccess the web server without requiring a signon. <strong>CA</strong> recommends that thisfeature be disabled <strong>for</strong> security reasons.1–48 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!