How is the CA SAF HFS security for the USS Hierarchical File System activated?
A site has two options to secure the Hierarchical File System (HFS):
CA SAF HFS security can be activated automatically during ACF2 initialization or dynamically just for the current duration of the IPL.
The GSO UNIXOPTS HFSSEC|NOHFSSEC controls the start of CA SAF HFS security during ACF2 initialization by default. When the GSO UNIXOPTS is set to HFSSEC, CA SAF HFS security will be active. The TSO, ACF command "SHOW UNIXOPTS" will display "HFS SECURITY ACTIVE: YES".
To dynamically activate CA SAF HFS security there are two methods.
Both of these methods will activate the CA SAF HFS security only for the duration of the current IPL. To activate CA SAF HFS security automatically at each IPL the GSO UNIXOPTS HFSSEC|NOHFSSEC can be used.
Details on activating CA SAF HFS Security can be found in the CA ACF2 for z/OS Administration Guide in Chapter 23: Controlling Access to the Hierarchical File System section 'Implementing CA SAF HFS Security'.