IBM Server GC28-1920-01 Manual de usuario

Busca en linea o descarga Manual de usuario para Servidores IBM Server GC28-1920-01. IBM Server GC28-1920-01 User's Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 110
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
OS/390
Place graphic in this
area. Outline is
keyline only. DO NOT PRINT.
IBM
Security Server (RACF)
Planning: Installation and Migration
GC28-1920-01
Vista de pagina 0
1 2 3 4 5 6 ... 109 110

Indice de contenidos

Pagina 1 - Security Server (RACF)

OS/390Place graphic in thisarea. Outline iskeyline only. DO NOT PRINT.IBM Security Server (RACF)Planning: Installation and Migration GC28-1920-

Pagina 2

viii OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 3

PLPAstorage requirement 32programming interfaceschanges to CDT 13data areas 16new routines 19templates 21publicationschanges to RACF library 19on

Pagina 4

SMF data unload utilityauditing considerations 47changes to 22SMF recordschanges to 45OpenEdition DCE support 46OpenEdition services 45SOMDOBJS cla

Pagina 5 - iii

78 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 6

IBM Let's face it, you have to search through a ton ofhardcopy manuals to locate all of the information youneed to secure your entire system.

Pagina 9

Communicating Your Comments to IBMOS/390Security Server (RACF)Planning: Installation and MigrationPublication No. GC28-1920-01If you especially like o

Pagina 10

Reader's Comments — We'd Like to Hear from YouOS/390Security Server (RACF)Planning: Installation and MigrationPublication No. GC28-1920-01Y

Pagina 11

Cut or FoldAlong LineCut or FoldAlong LineReader's Comments — We'd Like to Hear from YouGC28-1920-01IBMFold and Tape Please do not staple F

Pagina 13

Figures1. Function Shipped In OS/390 Release 1 Security Server (RACF) ... 52. Function Introduced After the Availability of OS/390 Release 1 Se

Pagina 14 - Trademarks

IBMProgram Number: 5645-001Printed in the United States of Americaon recycled paper containing 10%recovered post-consumer fiber.Drop in Back CoverIma

Pagina 15 - About This Book

x OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 16 - Softcopy Publications

NoticesReferences in this publication to IBM products, programs, or services do not implythat IBM intends to make these available in all countries

Pagina 17 - RACF Courses

TrademarksThe following terms are trademarks of the IBM Corporation in the United States orother countries or both:  AS/400  BookManager  C

Pagina 18 - Other Sources of Information

About This BookThis book contains information about the Resource Access Control Facility (RACF),which is part of the OS/390 Security Server. The Se

Pagina 19 - About This Book

 Chapter 7, “Administration Considerations” on page 37, summarizes changesto administration procedures for the new release of RACF. Chapter 8, “

Pagina 20 - OS/390 Up and Running!

RACF CoursesThe following RACF classroom courses are also available:Effective RACF Administration, H3927MVS/ESA RACF Security Topics, H3918Impl

Pagina 21 - About This Book xix

Other Sources of InformationIBM provides customer-accessible discussion areas where RACF may bediscussed by customer and IBM participants. Other i

Pagina 22

You can get sample code, internally-developed tools, and exits to help you useRACF. All this code works1, but is not officially supported. Each too

Pagina 24

Elements and Features in OS/390You can use the following table to see the relationship of a product you are familiar with and how it isreferred to

Pagina 25

Product Name and Level Name in OS/390 Base orOptional OpenEdition Application Services  OpenEdition Application Services base OpenEdition DCE Ba

Pagina 26

xx OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 27 - Reference

Summary of ChangesSummary of Changesfor GC28-1920-01OS/390 Release 2This book contains new information for OS/390 Release 2 Security Server (RACF).

Pagina 28

xxii OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 29 - Chapter 2. Release Overview

Chapter 1. Planning for MigrationThis chapter provides information to help you plan your installation's migration tothe new release of RACF. B

Pagina 30 - OS/390 OpenEdition DCE

Installation ConsiderationsBefore installing a new release of RACF, you must determine what updates areneeded for IBM-supplied products, system l

Pagina 31 - Concepts

Auditing ConsiderationsAuditors who are responsible for ensuring proper access control and accountabilityfor their installation are interested in

Pagina 32 - SystemView for MVS

4 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 33

Chapter 2. Release OverviewThis chapter lists the new and enhanced features of RACF for OS/390 Release 2.It also lists the support that has not be

Pagina 34 - Year 2000

OS/390 IBMSecurity Server (RACF)Planning: Installation and Migration GC28-1920-01

Pagina 35

Figure 2 on page 6 identifies function introduced after the availability of OS/390Release 1 Security Server (RACF).Figure 3 identifies function in

Pagina 36 - Function Not Upgraded

OS/390 OpenEdition DCE single signon support uses to sign in an authenticatedOS/390 user to DCE.The RACF support for OS/390 OpenEdition DCE include

Pagina 37 - OS/390 Release 2

OS/390 OpenEditionOS/390 Release 2 OpenEdition adds new capabilities for which RACF providessupport.Authorizing and Auditing Server Access to the

Pagina 38 - Commands

so that the user's information can be customized independently of the user'sworkstation type.The SystemView Launch window lets users log

Pagina 39

 Output and notifications from commands that were directed via the AT orONLYAT keywords. These are returned to the system on which the directedco

Pagina 40 - Data Areas

the IRRDCR00 module to allow customers to convert a 3-byte packed decimal dateto a 4-byte packed decimal date, using RACF's interpretation of

Pagina 41 - Messages

The PTF must be applied to all systems in the sysplex in order for theseenhancements to take effect. However, systems with and without the PTF app

Pagina 42 - Changed Messages

Chapter 3. Summary of Changes to RACF Components forOS/390 Release 2This chapter summarizes the new and changed components of OS/390 Release 2Secur

Pagina 43

Figure 7 lists classes for which there are changes.Figure 6 (Page 2 of 2). New ClassesClass Name Description SupportFILE This class controls

Pagina 44 - Templates

Figure 8. Changes to RACF CommandsCommand Description Supportall If an attempt is made to invoke a RACF commandwhen RACF is not enabled, RACF iss

Pagina 45 - Utilities

Note Before using this information and the product it supports, be sure to read the general information under “Notices” on page xi.Second Editio

Pagina 46

Data AreasFigure 9 lists changed general-use programming interface (GUPI) data areas forSAF to support RACF for OS/390 Release 2.Figure 10 lists

Pagina 47 - Migration Strategy

Figure 11. Changed Exits for RACFExit Description SupportICHRCX01ICHRCX02For unauthenticated client ACEEs, the RACROUTEREQUEST=AUTH preprocessing

Pagina 48 - Software Requirements

New MessagesThe following messages are added:RACF Initialization Messages: ICH562IRACF Processing Messages: IRR418IDynamic Parse (IRRDPI00 Comman

Pagina 49 - Compatibility

PanelsFigure 13 lists RACF panels that are changed.Figure 13. Changed Panels for RACFPanel Description SupportICHP41IICHP42IExisting panels for

Pagina 50

SYS1.SAMPLIBFigure 16 identifies changes to RACF members of SYS1.SAMPLIB.Figure 16. Changes to SYS1.SAMPLIBMember Description SupportIRRADULD T

Pagina 51 - Enabling RACF

Figure 17. Changes to TemplatesTemplate Description of Change SupportGeneral A new SVFMR segment provides the followinginformation:Field Descrip

Pagina 52

Figure 18. Changes to UtilitiesUtility Description of Change SupportIRRADU00 The SMF data unload utility has been updated tosupport unloading da

Pagina 53 - Programmer's Guide

Chapter 4. Planning ConsiderationsThis chapter describes the following high-level planning considerations forcustomers upgrading to Security Serve

Pagina 54

RACROUTE REQUEST=EXTRACT,TYPE=EXTRACT or TYPE=REPLACEbefore installing OS/390 Release 2 Security Server (RACF). In addition to thisbook you should

Pagina 55

Figure 19. Software Requirements for New FunctionFunction Software RequirementsOS/390 OpenEdition DCE interoperabilitysupportOpenEdition/MVS Rele

Pagina 57 - Customer Additions to the CDT

26 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 58

Chapter 5. Installation ConsiderationsThis chapter describes changes of interest to the system programmer installingOS/390 Release 2 Security Serv

Pagina 59 - Exit Processing

prefixIs a value you specify with the PREFIX keyword on theTARGET commandsysnameIs the system name. This name must match the value in theCVTSNAME

Pagina 60 - IRRSXT00 Installation Exit

the description of the TARGET command in OS/390 Security Server (RACF)Command Language Reference for details.If any of the INMSG or OUTMSG workspac

Pagina 61

////// //// RRSFALTR: //// //// IDCAMS JOB to rename the workspace data

Pagina 62 - Single Signon to DCE

//RRSFALTR JOB 'JOB TO RENAME WORKSPACE DATA SETS',MSGLEVEL=1,1//// USE A JOBCAT OR STEPCAT WHERE NEEDED TO POINT TO THE CATALOG// THA

Pagina 63

RACF Storage ConsiderationsThis section discusses storage considerations for RACF. Virtual StorageFigure 21 estimates RACF virtual storage usage,

Pagina 64 - Threads and Security

Figure 21 (Page 2 of 2). RACF Estimated Storage UsageStorage Subpool Usage How to Estimate SizeELSQA Connect group table 64 + (48 × number_of

Pagina 65 - Restrictions

Templates for RACF on OS/390 Release 2The RACF database must have templates at the Security Server (RACF) Release 2level in order for RACF to func

Pagina 66

Chapter 6. Customization ConsiderationsThis chapter identifies customization considerations for RACF.For additional information, see OS/390 Securi

Pagina 67

iv OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 68

– The first check uses the client ACEE. This is the ACEE that is associatedwith the current task. If the request is successful, the second check i

Pagina 69 - SMF Records

Chapter 7. Administration ConsiderationsThis chapter summarizes the changes to administration procedures that the securityadministrator should be

Pagina 70

database. The mvsexpt utility takes a specified input file or the DCEregistry for each principal specified and creates the RACF DCE segmentand pro

Pagina 71 - SMF Data Unload Utility

 The MVS user must have saved the current DCE password in the RACF DCEsegment by invoking the DCE storepw command.Note: Users still need to maint

Pagina 72

OpenEdition Planning, and in OS/390 OpenEdition Programming: AssemblerCallable Services Reference. The C language support for thepthread_security_

Pagina 73 - Enabling and Disabling RACF

Changes to RACF Authorization ProcessingExtensions have been introduced to RACF's processing of authorization requests inwhich both the RACF i

Pagina 74

resources. Profiles must reside in storage before RACROUTEREQUEST=FASTAUTH can be used to verify a user's access to a resource. The client/s

Pagina 75 - Year 2000 Support

SystemView for MVSBefore an installation can use SystemView for MVS, the security administratormust: Create profiles in the SYSMVIEW class for Sys

Pagina 76

44 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 77 - Programming Interfaces

Chapter 8. Auditing ConsiderationsThis section summarizes the changes to auditing procedures for the RACF:  SMF records Report writer utility

Pagina 78 -  “Routines” on page 19

ContentsNotices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xiTrademarks . . . . . . . . . . . . . . . .

Pagina 79

For more information on SMF records, see OS/390 Security Server (RACF) Macrosand Interfaces.Figure 23 (Page 2 of 2). Changes to SMF RecordsR

Pagina 80

Auditing OS/390 OpenEdition DCE SupportRACF provides one new audit function code (94) to audit OS/390 OpenEdition DCEsupport.Auditing SystemView fo

Pagina 81 - APAR OW14451

48 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 82 - Actions Required

Chapter 9. Operational ConsiderationsThis section summarizes the changes to operating procedures for RACF forOS/390 Release 2.Enhancements to the

Pagina 83 - APAR OW15408

50 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 84

Chapter 10. Application Development ConsiderationsApplication development is the process of planning, designing, and codingapplication programs tha

Pagina 85 - Chapter 13. Scenarios

The security administrator has the option of enforcing the use of both theapplication server's RACF identity and the RACF identity of the cli

Pagina 86 - On MIAMI2:

For more information on the convert_id_np (BPX1CID) callable service, see OS/390OpenEdition Programming: Assembler Callable Services Reference. The

Pagina 87 - On ORLANDO:

 “Macros” on page 17 “Templates” on page 20 “Utilities” on page 21 “Routines” on page 1954 OS/390 V1R2.0 Security Server (RACF) Planning: Inst

Pagina 88

Chapter 11. General User ConsiderationsRACF general users use RACF to: Log on to the system Access resources on the system Protect their own res

Pagina 89 - Glossary

Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17Panels . . . . . . . . . . . . . . . . . . . . . . .

Pagina 90

56 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 91 - Glossary 67

Chapter 12. NJE ConsiderationsSeveral APARs shipped on OS/390 Release 2 Security Server (RACF) haveimplications for NJE. APAR OW14451OS/390 Releas

Pagina 92

Actions RequiredWith OW08457 and OW14451, group propagation and group translation has beenfixed for NODES profiles, both for batch jobs and for S

Pagina 93 - Glossary 69

List all GROUPJ and GROUPS NODES profiles that have a UACC value greaterthan or equal to READ, recording the profile names and all keywords necessa

Pagina 94

60 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Pagina 95 - Glossary 71

Chapter 13. ScenariosThis chapter contains scenarios that might help you in planning your migration toSecurity Server (RACF) Release 2.Migrating a

Pagina 96 - DFP segment

2. Issue TARGET DORMANT commands from the operator's console to make allRRSF conversations dormant:prefixTARGET NODE(MIAMI1) DORMANTprefixTAR

Pagina 97

5. Issue a TARGET command from the operator's console to define systemSYSTEM1 as the MAIN system for the multisystem node. (Issuing thiscomman

Pagina 98

On MIAMI2: 1. Issue a TARGET command from the operator's console to define theconnection with ORLANDO.prefixTARGET NODE(ORLANDO) OPERATIVEPR

Pagina 99 - Index 75

GlossaryAaccess. The ability to obtain the use of a protectedresource.access authority. An authority related to a request fora type of access to

Pagina 100

Chapter 9. Operational Considerations . . . . . . . . . . . . . . . . . . . . . 49Enhancements to the RESTART Command ... 49Enab

Pagina 101 - (continued)

user ID on the same or a different RRSF node. Beforea command can be directed from one user ID toanother, a user ID association must be defined be

Pagina 102

FFASTAUTH request. The issuing of the RACROUTEmacro with REQUEST=FASTAUTH specified. Theprimary function of a FASTAUTH request is to check auser&a

Pagina 103 - Index

is the local LU, and the LU through whichcommunication is received is the partner LU.local node. The RRSF node from whose point of viewyou are ta

Pagina 104

 Daemon processes, which do systemwide functionsin user mode, such as printer spooling Kernel processes, which do systemwide functions inkernel m

Pagina 105

RRSF nodes that are logically connected, from MVSX'spoint of view MVSY is a remote node, and from MVSY'spoint of view MVSX is a remote n

Pagina 106

sysplex communication. An optional RACF functionthat allows the system to use XCF services andcommunicate with other systems that are also enabled

Pagina 107 - Phone No

OpenEdition MVS, a string that is used to identify auser.user profile. A description of a RACF-defined userthat includes the user ID, user name,

Pagina 108 - BUSINESS REPLY MAIL

IndexAADDUSER command 15administrationclassroom courses xvadministration considerationsmigration 2Airline Control System/MVS, support for 11ALCS/

Pagina 109

DCE support (continued)auditing considerations 47command changes 15controlling access to R_dceruid callable service 42DCEUUIDS class 13deleting RA

Pagina 110 - Back Cover

JJCICSJCT class 14, 53JCL for renaming workspace data sets 30KKCICSJCT class 14, 53KEYSMSTR class 14Llibrary, RACF publicationschanges to 19LSQAsto

Comentarios a estos manuales

Sin comentarios