RACF to Top Secret commands for zVTP software.
search cancel

RACF to Top Secret commands for zVTP software.

book

Article ID: 259053

calendar_today

Updated On:

Products

Top Secret

Issue/Introduction

Need the below RACF commands for IBM Z Virtual Test Platform (zVTP) converted to Top Secret commands:

RDEFINE FACILITY BPX.SERVER UACC(NONE)

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCRSE)

SETROPTS RACLIST(FACILITY) REFRESH

RDEFINE PTKTDATA FEKAPPL UACC(NONE) SSIGNON(KEYMASKED(key16)) APPLDATA('NO REPLAY PROTECTION – DO NOT CHANGE') DATA('IBM® EXPLORER FOR Z/OS')

RDEFINE PTKTDATA IRRPTAUTH.FEKAPPL.* UACC(NONE) DATA('IBM EXPLORER FOR Z/OS')

PERMIT IRRPTAUTH.FEKAPPL.* CLASS(PTKTDATA) ACCESS(UPDATE) ID(STCRSE)

PERMIT IRRPTAUTH.FEKAPPL.* CLASS(PTKTDATA) ACCESS(UPDATE) ID(STCAPI)

SETROPTS RACLIST(PTKTDATA) REFRESH

RDEFINE APPL FEKAPPL UACC(READ)

DATA('IBM Explorer for z/OS')

SETROPTS RACLIST(APPL) REFRESH

RDEFINE FACILITY BPX.SERVER UACC(NONE)

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCRSE)

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCAPI)

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCDBM)

SETROPTS RACLIST(FACILITY) REFRESH

PERMIT JES%.** CLASS(OPERCMDS) ACCESS(UPDATE) WHEN(CONSOLE(JMON)) ID(*)

RALTER PROGRAM ** UACC(READ) ADDMEM('SYS1.LINKLIB'//NOPADCHK)

RALTER PROGRAM ** UACC(READ) ADDMEM('SYS1.CSSLIB'//NOPADCHK)

RALTER PROGRAM ** UACC(READ) ADDMEM('CEE.SCEERUN'//NOPADCHK)

RALTER PROGRAM ** UACC(READ) ADDMEM('CEE.SCEERUN2'//NOPADCHK)

RALTER PROGRAM ** UACC(READ) ADDMEM('ISP.SISPLOAD'//NOPADCHK)

SETROPTS WHEN(PROGRAM) REFRESH

 

Environment

Release : 16.0

Resolution

RDEFINE FACILITY BPX.SERVER UACC(NONE)
TSS ADD(dept) IBMFAC(BPX.SERVER) ***May already be owned. May be owned at the HLQ of BPX.

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCRSE)
TSS PERMIT(STCRSE) IBMFAC(BPX.SERVER) ACCESS(UPDATE) ***Assumes you already have an acid STCRSE defined.

SETROPTS RACLIST(FACILITY) REFRESH
No TSS Equivalent.

RDEFINE PTKTDATA FEKAPPL UACC(NONE) SSIGNON(KEYMASKED(key16)) APPLDATA('NO REPLAY PROTECTION – DO NOT CHANGE') DATA('IBM® EXPLORER FOR Z/OS')
TSS ADD(NDT) PSTKAPPL(FEKAPPL) SESSKEY(key16     ) SIGNMULTI

RDEFINE PTKTDATA IRRPTAUTH.FEKAPPL.* UACC(NONE) DATA('IBM EXPLORER FOR Z/OS')
TSS ADD(owningacid) PTKTDATA(IRRPTAUTH.FEKAPPL.) 

PERMIT IRRPTAUTH.FEKAPPL.* CLASS(PTKTDATA) ACCESS(UPDATE) ID(STCRSE)
TSS PER(STCRSE) PTKTDATA(IRRPTAUTH.FEKAPPL.) ACC(UPDATE) 

PERMIT IRRPTAUTH.FEKAPPL.* CLASS(PTKTDATA) ACCESS(UPDATE) ID(STCAPI)
TSS PER(STCAPI) PTKTDATA(IRRPTAUTH.FEKAPPL.) ACC(UPDATE) ***Assumes you already have an acid of STCAPI defined.

SETROPTS RACLIST(PTKTDATA) REFRESH
No TSS Equivalent.
 
RDEFINE APPL FEKAPPL UACC(READ) DATA('IBM Explorer for z/OS')
TSS ADD(dept) APPL(FEKAPPL) ***Again, this may already be owned.

SETROPTS RACLIST(APPL) REFRESH
No TSS Equivalent.
 
RDEFINE FACILITY BPX.SERVER UACC(NONE)
Done above.

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCRSE)
Done above.

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCAPI)
TSS PERMIT(STCAPI) IBMFAC(BPX.SERVER) ACCESS(UPDATE)

PERMIT BPX.SERVER CLASS(FACILITY) ACCESS(UPDATE) ID(STCDBM)
TSS PERMIT(STCDBM) IBMFAC(BPX.SERVER) ACCESS(UPDATE) ***Assumes you already have an acid STCDBM defined.

SETROPTS RACLIST(FACILITY) REFRESH
No TSS Equivalent. 

PERMIT JES%.** CLASS(OPERCMDS) ACCESS(UPDATE) WHEN(CONSOLE(JMON)) ID(*)
TSS ADD(dept) OPERCMDS(JES%.) ***May already be owned.
TSS PERMIT(ALL) OPERCMDS(JES%.) ACCESS(UPDATE) 

RALTER PROGRAM ** UACC(READ) ADDMEM('SYS1.LINKLIB'//NOPADCHK)
TSS PERMIT(ALL) DSN(SYS1.LINKLIB) ACCESS(FETCH)

RALTER PROGRAM ** UACC(READ) ADDMEM('SYS1.CSSLIB'//NOPADCHK)
TSS PERMIT(ALL) DSN(SYS1.CSSLIB) ACCESS(FETCH)

RALTER PROGRAM ** UACC(READ) ADDMEM('CEE.SCEERUN'//NOPADCHK)
***Make sure that DSN(CEE.) is owned:
TSS ADD(dept) DSN(CEE.)
TSS PERMIT(ALL) DSN(CEE.SCEERUN) ACCESS(FETCH)

RALTER PROGRAM ** UACC(READ) ADDMEM('CEE.SCEERUN2'//NOPADCHK)
TSS PERMIT(ALL) DSN(CEE.SCEERUN2) ACCESS(FETCH)

RALTER PROGRAM ** UACC(READ) ADDMEM('ISP.SISPLOAD'//NOPADCHK)
***Make sure that DSN(ISP.) id owned:
TSS ADD(dept) DSN(ISP.)
TSS PERMIT(ALL) DSN(ISP.SISPLOAD) ACCESS(FETCH)

SETROPTS WHEN(PROGRAM) REFRESH
No TSS Equivalent.