IBM GC28-1920-01 manual Administration Considerations, Cross-Linking Between RACF Users, signon

Page 61
Chapter 7. Administration Considerations

Chapter 7. Administration Considerations

This chapter summarizes the changes to administration procedures that administrator should be aware of. For more information,OS/390 Securitysee

Server (RACF) Security Administrator's. Guide

OS/390 OpenEdition DCE

The

interoperation of RACF with OS/390 OpenEdition DCE enables DCE

application servers

on

MVS

to map a

DCE

user(principal)identoitya RACF

user

ID. The mapping

of

a

DCE

principal

to

a RACF usercrossID -linkingis .known as

The

cross-linking

information

contained

in

the RACF database

can be use

ŸOS/390 OpenEdition DCE, for determining which MVS users are eligible

OS/390 OpenEdition DCE single signon to DCE

ŸApplication servers residing on OS/390, to determine the RACF user I clients. For more information on application servers and their use of cross-linking contained in RACF, see “OS/390 OpenEdition DCE Application Considerations” on page 39.

To support crossthe -linkingandsingle signon to DCEfeatures, RACF provides:

Ÿ The DCE segment for the RACF user profile

ŸThe DCEUUIDS general resource class

The

DCE segment,

defined

to the

RACF

user profile,

associates

a

DCE

with

the

RACF

user profile. See Figure 17

on

page 20

for

the

contents

segment.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

The

DCEUUIDS

general

resource

class

contains

the cross-linking informatio

each

RACF/DCE

user. Profiles defined to the

RACF DCEUUIDS

class

associ

DCE principal

with

a

RACF

user

ID

on

a particular system

that

is

par

cell.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

The

security

administrator must work with the DCE administrator

to

def

profiles

to

supportcrossthe-linking andsingle

signon

to

DCEfeatures.

 

 

 

Cross-Linking Between RACF Users

 

and

DCE

Principals

 

 

 

Profiles in the DCEUUIDS class establish a

cross-link between a DCE p

UUID and a RACF user ID. Two OpenEdition DCE utilities administer DCE

information

in

the

RACF

database and create the initial cross-link info

between the

RACF

user

profile and the DCE principal registry:

mvsimpt

is

a

two-pass

utility

that

creates

DCE principal entries in t

 

registry for

 

the

set of

RACF

users

chosen to be cross-linked

 

the output from the RACF database unload utility. The unloaded

 

database

is

 

sorted

by the administrator according to RACF u

 

a RACF DCE segment and

filtered by the utility according to

 

entries

from

previous

mvsimpt

and mvsexpt processing.

mvsexpt

is

a

two-pass

utility that populates a RACF database with in

 

a

set

of

DCE

principals. It creates and updates the RACF DC

 

segment

for

each

DCE

principal

being

cross-linked with the RACF

 Copyright IBM Corp. 1994,

1996

 

 

 

 

 

 

 

 

 

 

37

Image 61
Contents OS/390 Security Server RACF Planning Installation and MigrationPlace graphic in this area. Outline is keyline only. DO NOT PRINT Page OS/390 1996. All Second Edition, SeptemberPage Page Migration ContentsCustomization Considerations Administration ConsiderationsAuditing Considerations Index Operational ConsiderationsChapter 10. ApplicationPage Figures Page Notices Trademarks About This Book How to Use ThisWho Should Use This Book xiiiSoftcopy Publications Where to Find More InformationŸ The OS/390 Security Server RACF Information , PackageSK2T-2180 ServerElements of Security RACF Installation - Student GG24-3971Notes Administration, H3927Using the Ÿ Tutorial Options for Tuning GG22RACFIBM Discussion Areas Other Sources of InformationInternet Sources listserv@uga.cc.uga.eduTo Request Copies of Publicationsxviii OS/390Features Product ServiceŸ OpenEditionOSA/SF V2R5TSO/EPage Summary of Changes Page Chapter 1. Planning Migration Planning ConsiderationsMigration Administration Considerations Installation ConsiderationsCustomization Considerations Operational Considerations Auditing ConsiderationsApplication Development Considerations General User ConsiderationsPage New and Enhanced Support Chapter 2. Release Overviewidentifies OS/390 OpenEdition DCEfunction introduced in OS/390 ReleaseCheck ConceptsAuditing the Passing of Access Rights Authorizing and Auditing Server Access to the CCS and WLM ServicesOS/390 OpenEdition SOMobjects for MVSRRSF Network Multisystem Nodesnon-main systemsYear OS/390 Enable and Disable FunctionsTARGET 1.10 NetViewclasses Facilityupdated for Function Not Upgradedidentifies function thatRelease Components for3. Summary of Class Descriptor Table CDTlists classes Commandswhich thereChapter 3. Summary of Changes to RACF Components for OS/390 15Release CommandExits Data Areaslists changed general-use programming interface GUPI data areMessages MacrosFigure 12 lists changes RACF macrosChanged Messages New MessagesMessages RACF Database Split/Merge Utility IRRUT400Publications Library PanelsRoutines Figure 13 lists RACF panels that areTemplates SYS1.SAMPLIBFigure 16 identifies changes to RACF members of SYS1.SAMPLIB RACROUTE REQUEST=EXTRACTFigure 18 lists changes to RACF utilities for OS/390 Release UtilitiesTemplate 0280 UtilityRACF Planning Installation and Migrationfor RACF OS/390 Security Server RACF Planning Installation and forMigrationChapter 4. Planning Considerations Migration StrategyHardware Requirements RACF Planning Installation and Migrationfor RACF 2.1, andSoftware Requirements RACF Migration and Planning for RACFCompatibility Considerations for Remote Sharing CompatibilityRequirements Page Enabling RACF Chapter 5. Installation ConsiderationsConsiderations Networksconfigured installationare in your existing workspace data sets when you install multisystem Rmust Chapter 5. Installation Considerations29nodename prefixsysname local-luprefix.local-node.local-node .INMSG Virtual Storage RACF Storage ConsiderationsThis section discusses storage considerations for RACF Figure 21 estimates RACF virtual storage usage, for planning purposesSubpool Customer Additions to the CDTOS/390 Release Templates for RACF oninformation, OS/390see Security Server SystemExit Processing Chapter 6. Customization Considerationsand IRRSXT00 Effects of OS/390 OpenEdition DCERACROUTE REQUEST=DEFINE Preprocessing Exit ICHRDX01 IRRSXT00 Installation ExitServer RACF Security Administrators. Guide Chapter 7. Administration ConsiderationsCross-Linking Between RACF Users signonSignon to DCEUUIDS ClassActivating OS/390 OpenEdition DCE Application Considerations single signon restrictionsOpenEditionsee DCE Administration .Guidethe DCE Encryption Key Library Reference OpenEdition Planning, and inOS/390 OpenEdition Programming AssemblerThreads and Restrictions Changes to RACF Authorization Processingcallable servicepthread orsecuritynp Utility Rdceruid Callable ServiceEnhancements to the SYSMVIEW Chapter 7. Administration Considerations43Page SMF Records Chapter 8. Auditing ConsiderationsAuditors Guide and OS/390 Server RACF MacrosAuditing New OS/390 ServicesInterfaces Auditing SystemView for MVS Support Auditing OS/390 OpenEdition DCE SupportReport Writer SMF Data Unload UtilityPage OS/390 Security Server RACF Command Language Referencefor more CommandChapter 9. Operational Considerations Enabling and DisablingPage 2000 Support Chapter 10. Application Development ConsiderationsServers 01yydddFpthread the securitynp New Application Services and SecurityNew Application Authorization ServiceChanges to the Class Descriptor Table Programming InterfacesŸ “Routines” on page Ÿ “Macros” on page Ÿ “Templates” on page Ÿ “Utilities” on pageConsiderations Chapter 11. General UserOpenEdition Reference forPage APAR OW14451 Chapter 12. NJE ConsiderationsOW08457 After Applying the PTFOW08457 Actions RequiredUACC NODESGROUP APAR OW15408FAILSAFE Page Migrating an Existing Chapter 13. ScenariosNodes RRSFOn MIAMI2 prefixTARGET NODEMIAMI2 SYSNAMESYSTEM2 LOCAL OPERATIVEprefixTARGET NODEORLANDO DELETE prefixTARGET NODEMIAMI2 DELETEOn ORLANDO RACF DiagnosisDELETE Note The prefixTARGET NODEORLANDO OPERATIVE PREFIX... PROTOCOL... WORKSPACEaccess Glossarydirection Page Seeinventory Seegeneral-use programmingprogramming Seemultisystem Seelogicallogical supervisory other.single-systemtask segment andDFP classes continued Index Acontinued Page SFSCMD SERVERKEYSMSTR utilitiescontinued Page Now you can! TheIBM Online Library Productivity IBM Edition OS/390 Security Server RACF Information Page Page comments Communicating Your Comments to IBMOS/390 Security Server RACF Planning Installation and Migration Readers Comments - Wed Like to Hear from YouPublication No. GC28-1920-01 Note CopiesREPLY MAILBUSINESS IBMPage Drop in Back Cover Image Here IBMGC28-192ð-ð1