IBM GC28-1920-01 manual NJE Considerations, APAR OW14451, OW08457, After Applying the PTF

Page 81
Chapter 12. NJE Considerations

Chapter 12. NJE Considerations

Several APARs shipped on OS/390 Release 2 Security Server (RACF) have implications for NJE.

APAR OW14451

OS/390 Release 2 Security Server

(RACF)

includes

a

PTF

that

provides

f

that

change

the

way

 

inbound

NJE

 

jobs

and

NJE

 

sysout

are

handled

by

your

installation

uses

 

NJE

and

RACF

nodes profiles

it

is imperative

tha

and understand this chapter before installing the new RACF release. Th

information

includes

a

 

brief overview of NJE security

before

and

af

this release and the actions required to assure that the PTF has n

consequences

on your

system. It also includes information on how you

the

enhanced

function

 

introduced

by this

PTF to

further

implement

sec

on your system.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Note:

APAR

OW08457

shipped

on

RACF

releases

prior

 

to

RACF

2.2. The

code

 

that shipped for OW08457 was in the RACF

2.2

base

 

program

(the

 

version)

and

OS/390

Release

1

Security

Server

(RACF).

OW14451

fix

 

some problems introduced by OW08457 that

are

in

the

 

RACF

2.2

b

 

OS/390 Release

1

Security

Server

(RACF). The

phrase

“prior

to

OW0

 

means

“prior

to

RACF 2.2 and prior to OS/390

Release

1 Security

 

(RACF).”

In

any

case, OS/390 Release 2 Security Server (RACF)

us

 

should be aware of the possible implications of the changes

O

 

OW14451

have

on

 

NJE

processing.

 

 

 

 

 

 

 

 

 

 

 

 

 

Before Applying the PTF

for

APAR

OW08457

 

 

 

 

 

 

 

 

Prior

to

the

application of

OW08457,

RACF

did not

perform any

security

or propagation for groups associated with NJE jobs or

SYSOUT. RACF us

profiles of the form NODEID.USER%.* ADDMEM(USERID)

with a

UACC

or

read

higher

to

translate

USERIDs

from the submitting

userid

to

an

executi

the receiving system. This type of translation was not

available

for

groups. The execution

group

became

the

default

group

of

the

transla

After Applying the PTF

for

APAR

OW08457

 

This

PTF enables

group translation and propagation for NJE jobs

and SYSO

With

this

fix

applied the submitting group is propagated to

become

group for jobs and the owning group for SYSOUT in the absence of a NODEID.GROUP%.GROUPID profiles. This service introduces the ability to

translate

groups

with

NODEID.GROUP%.GROUPID

 

profiles by

using

an

ADDMEM

with a

UACC of READ or higher. An ADDMEM

of

&DFLTGRP

will

cause

the

USERIDs

default

group

to be

used as

the

execution

or

owning

group.

NONE on the GROUP% profile will work as

it

always

has. Because

NODES

profiles

only

affect

inbound

NJE work,

no

profile

changes

need

to be

outbound

NJE

work.

 

 

 

 

 

 

 

 

 

 

 Copyright IBM Corp. 1994, 1996

57

Image 81
Contents Security Server RACF Planning Installation and Migration OS/390Place graphic in this area. Outline is keyline only. DO NOT PRINT Page OS/390 1996. All Second Edition, SeptemberPage Page Migration ContentsAdministration Considerations Customization ConsiderationsAuditing Considerations Index Operational ConsiderationsChapter 10. ApplicationPage Figures Page Notices Trademarks About This Book How to Use ThisWho Should Use This Book xiiiSoftcopy Publications Where to Find More InformationŸ The OS/390 Security Server RACF Information , PackageSK2T-2180 ServerElements of Security RACF Installation - Student GG24-3971Notes Administration, H3927Using the Ÿ Tutorial Options for Tuning GG22RACFIBM Discussion Areas Other Sources of InformationInternet Sources listserv@uga.cc.uga.eduTo Request Copies of PublicationsOS/390 xviiiFeatures Product ServiceŸ OpenEditionOSA/SF V2R5TSO/EPage Summary of Changes Page Migration Planning Considerations Chapter 1. PlanningMigration Installation Considerations Administration ConsiderationsCustomization Considerations Operational Considerations Auditing ConsiderationsApplication Development Considerations General User ConsiderationsPage New and Enhanced Support Chapter 2. Release Overviewidentifies OS/390 OpenEdition DCEfunction introduced in OS/390 ReleaseCheck ConceptsAuditing the Passing of Access Rights Authorizing and Auditing Server Access to the CCS and WLM ServicesOS/390 OpenEdition SOMobjects for MVSRRSF Network Multisystem Nodesnon-main systemsOS/390 Enable and Disable Functions YearTARGET 1.10 NetViewclasses Facilityupdated for Function Not Upgradedidentifies function thatRelease Components for3. Summary of Class Descriptor Table CDTlists classes Commandswhich thereChapter 3. Summary of Changes to RACF Components for OS/390 15Release CommandExits Data Areaslists changed general-use programming interface GUPI data areMessages MacrosFigure 12 lists changes RACF macrosChanged Messages New MessagesMessages RACF Database Split/Merge Utility IRRUT400Publications Library PanelsRoutines Figure 13 lists RACF panels that areTemplates SYS1.SAMPLIBFigure 16 identifies changes to RACF members of SYS1.SAMPLIB RACROUTE REQUEST=EXTRACTUtilities Figure 18 lists changes to RACF utilities for OS/390 ReleaseTemplate 0280 UtilityRACF Planning Installation and Migrationfor RACF OS/390 Security Server RACF Planning Installation and forMigrationChapter 4. Planning Considerations Migration StrategyHardware Requirements RACF Planning Installation and Migrationfor RACF 2.1, andSoftware Requirements RACF Migration and Planning for RACFCompatibility Compatibility Considerations for Remote SharingRequirements Page Enabling RACF Chapter 5. Installation ConsiderationsConsiderations Networksconfigured installationare in your existing workspace data sets when you install multisystem Rmust Chapter 5. Installation Considerations29nodename prefixsysname local-luprefix.local-node.local-node .INMSG Virtual Storage RACF Storage ConsiderationsThis section discusses storage considerations for RACF Figure 21 estimates RACF virtual storage usage, for planning purposesSubpool Customer Additions to the CDTOS/390 Release Templates for RACF oninformation, OS/390see Security Server SystemExit Processing Chapter 6. Customization Considerationsand IRRSXT00 Effects of OS/390 OpenEdition DCERACROUTE REQUEST=DEFINE Preprocessing Exit ICHRDX01 IRRSXT00 Installation ExitServer RACF Security Administrators. Guide Chapter 7. Administration ConsiderationsCross-Linking Between RACF Users signonDCEUUIDS Class Signon toActivating single signon restrictionsOpenEditionsee DCE Administration .Guide OS/390 OpenEdition DCE Application Considerationsthe DCE Encryption Key OpenEdition Planning, and inOS/390 OpenEdition Programming Assembler Library ReferenceThreads and Changes to RACF Authorization Processing Restrictionscallable servicepthread orsecuritynp Rdceruid Callable Service UtilityEnhancements to the SYSMVIEW Chapter 7. Administration Considerations43Page SMF Records Chapter 8. Auditing ConsiderationsAuditors Guide and OS/390 Server RACF MacrosServices Auditing New OS/390Interfaces Auditing SystemView for MVS Support Auditing OS/390 OpenEdition DCE SupportReport Writer SMF Data Unload UtilityPage OS/390 Security Server RACF Command Language Referencefor more CommandChapter 9. Operational Considerations Enabling and DisablingPage 2000 Support Chapter 10. Application Development ConsiderationsServers 01yydddFpthread the securitynp New Application Services and SecurityNew Application Authorization ServiceChanges to the Class Descriptor Table Programming InterfacesŸ “Routines” on page Ÿ “Macros” on page Ÿ “Templates” on page Ÿ “Utilities” on pageConsiderations Chapter 11. General UserOpenEdition Reference forPage APAR OW14451 Chapter 12. NJE ConsiderationsOW08457 After Applying the PTFOW08457 Actions RequiredUACC NODESAPAR OW15408 GROUPFAILSAFE Page Migrating an Existing Chapter 13. ScenariosNodes RRSFOn MIAMI2 prefixTARGET NODEMIAMI2 SYSNAMESYSTEM2 LOCAL OPERATIVEprefixTARGET NODEORLANDO DELETE prefixTARGET NODEMIAMI2 DELETERACF Diagnosis On ORLANDODELETE Note The prefixTARGET NODEORLANDO OPERATIVE PREFIX... PROTOCOL... WORKSPACEGlossary accessdirection Page Seegeneral-use programming Seeinventoryprogramming Seemultisystem Seelogicallogical supervisory other.single-systemtask segment andDFP classes continued Index Acontinued Page SERVER SFSCMDKEYSMSTR utilitiescontinued Page IBM  Now you can! TheIBM Online Library ProductivityEdition OS/390 Security Server RACF Information Page Page comments Communicating Your Comments to IBMOS/390 Security Server RACF Planning Installation and Migration Readers Comments - Wed Like to Hear from YouPublication No. GC28-1920-01 Note CopiesREPLY MAILBUSINESS IBMPage IBM Drop in Back Cover Image HereGC28-192ð-ð1