IBM GC28-1920-01 manual Auditing New OS/390, Services, Interfaces

Models: GC28-1920-01

1 110
Download 110 pages 26.8 Kb
Page 70
Image 70
Interfaces.

Figure 23 (Page 2 of 2). Changes to SMF Records

Record Type

80

80

80

Record

Description

of Change

Support

Field

 

 

 

Relocate

For event code 2, this SMF recordOS/390

65

contains

flags indicating

the ACEE type:OpenEdition

 

 

 

DCE

ŸUnauthenticated client

ŸAuthenticated client

ŸServer

Relocate

For

event

codes

28,

29,

30,

31,

OS/39032, 33,

315

34,

41,

44,

47,

48,

54,

55, 56,

OpenEdition57,63, and

 

64,

this

SMF

record

 

contains

a linkDCEvalue

 

to connect client and server audit records.

Relocate

For

event

codes

28,

29,

30,

31, OS/39032, 33,

316

34,

41,

44,

47,

48,

54,

55, 56,

OpenEdition57,63, and

 

64,

this

SMF

record

 

contains

flags DCE

 

indicating

the

ACEE

 

type:

 

 

 

ŸUnauthenticated client

ŸAuthenticated client

ŸServer

For

more information on SMF records,OS/390seeSecurity Server (RACF) Macros

and

Interfaces.

Auditing New OS/390

OpenEdition

MVS

Services

 

 

 

 

 

 

 

 

 

 

 

 

 

 

RACF

provides

two new audit function codes

(99 and 100) to audit two ne

OS/390

OpenEdition

MVS

services: a

new

console

communications

service (CCS)

and a new workload manager (WLM) service. Creation of the audit records

controlled

by

the

existing

PROCESS

class. Customers

that

are

not

already

auditing

the

PROCESS

class

must SETROPTSissue

AUDIT(PROCACT)

to

obtain

the

 

new

SMF

records,

whereoption is

ALWAYS,

NEVER, SUCCESSES,

FAILURES,

 

 

 

 

or DEFAULT. Customers that are already auditing the PROCESS class

 

 

automatically receive the new SMF records. These customers might see an

increase in the number of SMF records that RACF writes during OpenEditio

processing.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

RACF also provides three new audit function

codes

(95,

96,

and

97)

to a

passing

of access

rights

from

one process

to

another. Creation

of

the

is

controlled

by the existing PROCACT class. Customers

that are

not

alrea

auditing

the

PROCACT

class

must SETROPTSissue

LOGOPTIONS(option(PROCACT))

 

 

 

to

obtain

the

new

SMF records,optionwhereis

ALWAYS,

NEVER,

SUCCESSES,

 

 

 

 

FAILURES,

or

DEFAULT.

Customers

that

are

already

auditing

the PROCACT

 

class automatically receive the new SMF records. These customers might s increase in the number of SMF records that RACF writes during OpenEditio processing.

46 OS/390 V1R2.0 Security Server (RACF) Planning: Installation and Migration

Page 70
Image 70
IBM GC28-1920-01 manual Auditing New OS/390, Services, Interfaces