12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Lotus Notes Server(To RACF, these comm<strong>and</strong>s mark all programs in these libraries as"NOPADCHK". This means that any program-restricted data set accessshould not have to list any of the programs from these libraries. In otherwords, this marks all programs from these libraries as being trusted <strong>and</strong>there<strong>for</strong>e exempt from any program accessed data set / PADS checks. Thesecomm<strong>and</strong>s are not applicable to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong>.)6. Install steps, which discuss permission bits <strong>and</strong> the "sticky bit", are related toOMVS file security itself <strong>and</strong> are unrelated to RACF. There<strong>for</strong>e, such stepsshould be followed as described.Lotus Notes ServerThe Lotus Notes Server (email) can run on a z/<strong>OS</strong> or <strong>OS</strong>/390 environment. Theexternal security interface requires a facility <strong>and</strong> a DOMINO console interface(identified in IBM as DOMCON). This interface facilitates sending comm<strong>and</strong>sfrom z/<strong>OS</strong> or <strong>OS</strong>/390 to stop, start <strong>and</strong> manage Lotus Notes Server runningunder UNIX Systems Services.The Lotus Notes Server requires an acid <strong>for</strong> the server started task <strong>and</strong> a groupacid. The following comm<strong>and</strong>s accomplish this using the IBM default values.TSS CREATE(LOTUSGRP) TYPE(GROUP) NAME(LOTUSGROUP) DEPT(OMVSDEPT)TSS ADD(LOTUSGRP) GID(6789)TSS CREATE(DOMCON) TYPE(USER) NAME('LOTUS STC ACID') PASS(password,0)DEPT(OMVSDEPT) FACILITY(STC)TSS ADD(DOMCON) GROUP(LOTUSGRP) DFLTGRP(LOTUSGRP)TSS ADD(STC) PROCNAME(?????) ACID(DOMCON)The above comm<strong>and</strong> adding the stc should be done <strong>for</strong> all LOTUS PROCs. Therecan be multiple procs associated with this address space beginning with"DOMIN".TSS ADD(DOMCON) UID(0) HOME(/u/domcon) OMVSPGM(/bin/sh)TSS PERMIT(DOMCON) IBMFAC(BPX.DAEMON) ACCESS(READ)TSS ADD(DEPTACID) DSN(DOMCOM.WTO.LOAD)TSS PERMIT(DOMCON) DSN(DOMCOM.WTO.LOAD) ACCESS(READ)1–50 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!