IBM Server OS/390 Manuale Utente

Navigare online o scaricare Manuale Utente per Software IBM Server OS/390. IBM Server OS/390 User's Manual Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa

Sommario

Pagina 1 - Security Server (RACF)

OS/390 IBM Security Server (RACF)Planning: Installation and Migration GC28-1920-03

Pagina 2

viii OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 3

TrademarksThe following terms are trademarks of the IBM Corporation in the United States orother countries or both:  AIX/6000  BookManager 

Pagina 4

x OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 5 - Contents

About This BookThis book contains information about the Resource Access Control Facility (RACF),which is part of the OS/390 Security Server. The Se

Pagina 6

 Chapter 6, “Customization Considerations” on page 29, highlights informationabout customizing function to take advantage of new support after th

Pagina 7

RACF CoursesThe following RACF classroom courses are also available:Effective RACF Administration, H3927MVS/ESA RACF Security Topics, H3918Impl

Pagina 8

Other Sources of InformationIBM provides customer-accessible discussion areas where RACF may bediscussed by customer and IBM participants. Other i

Pagina 9

You can get sample code, internally-developed tools, and exits to help you useRACF. All this code works in our environment, at the time we make it

Pagina 10

xvi OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 11 - Trademarks

Summary of Changes| Summary of Changes| for GC28-1920-03| OS/390 Version 2 Release 4| This book contains primarily new information for OS/390 Versi

Pagina 13 - About This Book

xviii OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 14 - Softcopy Publications

Chapter 1. Planning for MigrationThis chapter provides information to help you plan your installation's migration tothe new release of OS/390

Pagina 15 - RACF Courses

Installation ConsiderationsBefore installing a new release of RACF, you must determine what updates areneeded for IBM-supplied products, system l

Pagina 16 - Other Sources of Information

Auditing ConsiderationsAuditors who are responsible for ensuring proper access control and accountabilityfor their installation are interested in

Pagina 17 - About This Book xv

4 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 18

Chapter 2. Release OverviewThis chapter lists the new and enhanced functions of RACF for OS/390 Release 4and gives a brief overview of each new fu

Pagina 19 - Summary of Changes

Enhancements to Support for OpenEdition ServicesEnhancements to RACF's support for OpenEdition services include: Extended ability to audit t

Pagina 20

The getUMAP and getGMAP services also look for default values. If getUMAP isgiven a UID as input and the corresponding USER profile has no OMVS seg

Pagina 21

 The ALTUSER command allows an administrator to reset a user's password toa temporary password or a default value. This command is modified

Pagina 22

system. This support provides a solution to many customers that find themselves insuch a situation.The PERMIT command has a new keyword to add user

Pagina 23 - Auditing Considerations

OS/390 IBMSecurity Server (RACF)Planning: Installation and Migration GC28-1920-03

Pagina 24

Enable/Disable ChangesOS/390 Version 2 Release 4 has a new product ID that affects the enable/disablefunction in all of its elements including th

Pagina 25 - Chapter 2. Release Overview

Chapter 3. Summary of Changes to RACF Components forOS/390 Release 4This chapter summarizes the new and changed components of OS/390 Release 4Secur

Pagina 26

Figure 2. Changed Callable ServicesCallableServiceName Description SupportinitUSP  If no OMVS segment is found in the user'sprofile, the i

Pagina 27 - Password History Enhancements

Figure 3. New ClassesName Description SupportDSNADM DB2 administrative authority class DB2GDSNBP Grouping class for buffer pool privileges DB2GDS

Pagina 28 - Program Control by System ID

Figure 4 (Page 2 of 3). Changes to RACF CommandsCommand Description SupportALTUSER This command supports the removal of all of theuser'

Pagina 29 - New FMID

Figure 4 (Page 3 of 3). Changes to RACF CommandsCommand Description SupportTARGET The new keyword WDSQUAL is added to theRACF TARGET command

Pagina 30 - Enable/Disable Changes

Figure 5. Changes to PSPI Data AreasData Area Description SupportAFC This data area maps the contents for the OpenEdition MVS security audit fun

Pagina 31 - OS/390 Release 4

RFXALET and RFXLOGS correspond to new fields in the RACROUTEREQUEST=FASTAUTH parameter list. These fields only exist in parameter listscreated with

Pagina 32 - Class Descriptor Table (CDT)

RALTER Command Messages: ICH11304ISETROPTS Command Messages: ICH14042IRACF Manager Error Messages: ICH51011IRACF Processing Messages: IRR410IRACF

Pagina 33 - Commands

Figure 7. New Panels for RACFPanel Description SupportICHP241n This panel enables you to add an entry for theconditional access list and to ident

Pagina 34

Note Before using this information and the product it supports, be sure to read the general information under “Notices” on page vii. Fourth Edit

Pagina 35 - Data Areas

Publications LibraryFigure 10 lists changes to the OS/390 Security Server (RACF) publications library.Note: You are able to print the softcopy do

Pagina 36

Chapter 4. Planning ConsiderationsThis chapter describes the following high-level planning considerations forcustomers upgrading to OS/390 Release

Pagina 37

–OS/390 Security Server (RACF) Planning: Installation and Migration forOS/390 Release 1.(GC28-1920-00)If you have RACF 1.9.2 installed, in additio

Pagina 38 - Deleted Messages

CompatibilityThis section describes considerations for compatibility between OS/390 Release 4Security Server (RACF) and OS/390 Release 3 Security

Pagina 39 - SYS1.SAMPLIB

24 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 40 - Publications Library

Chapter 5. Installation ConsiderationsThis chapter describes the following changes of interest to the system programmerinstalling OS/390 Release 4

Pagina 41 - Migration Strategy

Figure 11 (Page 2 of 3). RACF Estimated Storage UsageStorageSubpool Usage How to Estimate SizeESQA RACF data sharing control area 300 (when

Pagina 42 - Hardware Requirements

Figure 11 (Page 3 of 3). RACF Estimated Storage UsageStorageSubpool Usage How to Estimate SizeECSA RACF data set descriptor table andextensio

Pagina 43 - RELEASE=2.4 Keyword on Macros

28 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 44

Chapter 6. Customization ConsiderationsThis chapter identifies customization considerations for OS/390 Release 4 SecurityServer (RACF).For additio

Pagina 45 - Virtual Storage

ContentsNotices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . viiTrademarks . . . . . . . . . . . . . . . .

Pagina 46

 Set the options in the RACF/DB2 external security module. To do this, seeOS/390 Security Server (RACF) System Programmer's Guide. Decide w

Pagina 47

Chapter 7. Administration ConsiderationsThis chapter summarizes the changes to administration procedures that the securityadministrator should be

Pagina 48

Enhancements of Global Access CheckingWhen you use RACROUTE REQUEST=AUTH processing (which utilizes globalaccess checking) for general resource cl

Pagina 49

Chapter 8. Auditing ConsiderationsThis section summarizes the changes to auditing procedures for SMF records. SMF RecordsFigure 12 summarizes chan

Pagina 50 - Exit Processing

34 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 51 - Password History Changes

Chapter 9. Application Development ConsiderationsApplication development is the process of planning, designing, and codingapplication programs that

Pagina 52 - RACROUTE REQUEST=LIST

36 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 53 - SMF Records

Chapter 10. General User ConsiderationsRACF general users use RACF to: Log on to the system Access resources on the system Protect their own res

Pagina 54

38 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 55 - FASTAUTH Changes

GlossaryAaccess. The ability to obtain the use of a protectedresource.access authority. An authority related to a request fora type of access to

Pagina 56

SYS1.SAMPLIB . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19Publications Library . . . . . . . . . . . . . . . . .

Pagina 57

DATASET classes. The table is generated by executingthe ICHERCDE macro once for each class. The classdescriptor table contains both the IBM provid

Pagina 58

Eentity. A user, group, or resource (for example, aDASD data set) that is defined to RACF.EXTRACT request. The issuing of the RACROUTEmacro with

Pagina 59 - Glossary

LLIST request. The issuing of the RACROUTE macrowith REQUEST=LIST specified. A LIST request buildsin-storage profiles for RACF-defined resources.

Pagina 60

posit. A number specified for each class in the classdescriptor table that identifies a set of flags that controlRACF processing options. See the

Pagina 61 - Glossary 41

set that is RACF-protected by a discrete profile mustalso be RACF-indicated.RACROUTE macro. An assembler macro thatprovides a means of calling RA

Pagina 62

supervisor. The part of a control program thatcoordinates the use of resources and maintains the flowof processing unit operations. Synonym for su

Pagina 63 - Glossary 43

security program for the system. The batch jobowner is specified on the USER parameter on theJOB statement or inherited from the submitter of thej

Pagina 64

How to Get Your RACF CDLet's face it, you have to search through a ton ofhardcopy manuals to locate all of the information youneed to secure y

Pagina 65 - Glossary 45

48 OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 66 - DFP segment

IndexAaccess list entryconditional 23standard 23ACEEALET keyword 16ADDUSER command 15administrationclassroom courses xiiiadministration consider

Pagina 67 - How to Get Your RACF CD

Figures1. New Callable Services ... 112. Changed Callable Services ... 123. New Classes . . .

Pagina 68

getGMAP callable service 6, 12getUMAP callable service 6, 12global access checking 10Hhardware requirementsplanning considerations 22HRF2240 9IIC

Pagina 69 - See also

RR_Admin callable service 8, 11RACFclassroom courses xiiipublicationson CD-ROM xiisoftcopy xiiRACF 1.9migration path from 22RACF 1.9.2migration pa

Pagina 71

Readers' Comments — We'd Like to Hear from YouOS/390Security Server (RACF)Planning: Installation and MigrationPublication No. GC28-1920-03O

Pagina 72

Cut or FoldAlong LineCut or FoldAlong LineReaders' Comments — We'd Like to Hear from YouGC28-1920-03IBMFold and Tape Please do not staple F

Pagina 74 - BUSINESS REPLY MAIL

IBMProgram Number: 5647-A01Printed in the United States of Americaon recycled paper containing 10%recovered post-consumer fiber.GC28-192ð-ð3

Pagina 75

vi OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration

Pagina 76 - GC28-192ð-ð3

NoticesReferences in this publication to IBM products, programs, or services do not implythat IBM intends to make these available in all countries

Commenti su questo manuale

Nessun commento