Assistance or best practices needed to roll out pass tickets and eventually MFA with TPX.
TPX® Session Management for z/OS
The sample SAMTs for ACF2 Top Secret , RACF, and SAF in hlq.CB0VDATV(ADMIN1) have been updated to change the default message #DFLTMSG) action from A (allow) to R (reject).
This change mitigates the potential security risk that is caused by new messages from an External Security System (ESM) during TPX signon.
New return codes and message IDs have also been added to the sample SAMT tables. These return codes and message IDs are related to generic signon credentials and multi-factor authentication messages that are generated from different ESMs. These additions maintain currency with new ESM codes and messages that may affect customers.
The following return codes and message IDs have been added for ACF2:
Return Code/ Message ID |
Action |
Cursor Position |
Suppress Message |
Substitute Message IDs |
#0001072 |
R |
SNUSERV |
N |
n/a |
The following return codes and message IDs have been added for
Top Secret
Return Code/ Message ID |
Action |
Cursor Position |
Suppress Message |
Substitute Message IDs |
#0007057 |
R |
SNUSERV |
N |
IENS004A IENS004B |
#0007099 |
R |
SNUSERV |
N |
n/a |
The following return codes and message IDs have been added for RACF:
Return Code/ Message ID |
Action |
Cursor Position |
Suppress Message |
Substitute Message IDs |
6C |
R |
SNUSERV |
N |
IENS004A IENS004B |
68 |
R |
SNUSERV |
N |
IENS004A IENS004B |
70 |
R |
SNUSERV |
N |
IENS004A IENS004B |
74 |
R |
SNUSERV |
N |
IENS004A IENS004B |
The following return codes and message IDs have been added for SAF:
Return Code/ Message ID |
Action |
Cursor Position |
Suppress Message |
Substitute Message IDs |
086C |
R |
SNUSERV |
N |
IENS004A IENS004B |
0868 |
R |
SNUSERV |
N |
IENS004A IENS004B |
0870 |
R |
SNUSERV |
N |
IENS004A IENS004B |
0874 |
R |
SNUSERV |
N |
IENS004A IENS004B |
3. Make sure panel Panel TEN1003 is updated to support passcode entry. For more information on sign-on panels, see Password Verification.
TPX supports using the LOCK/UNLOCK function for users who sign on with a password, passphrase, or Multi-Factor Authentication and Advanced Authentication Mainframe (MFA/AAM) code.
Panel TEN1023 is modified to accept a passcode (password, passphrase, or MFA/AAM code) to unlock the terminal. For more information on using panel TEN1023 for LOCK/UNLOCK, see Lock and Unlock Your Terminal.
Users who sign in without a passcode or with a Pass Ticket must use a lock word to lock and unlock the terminal.
Apply the following PTFs for the LOCK/UNLOCK enhancement:
If you use the TPX user signon and signoff exit TPXUSNSF has been enhanced with the addition of call point 52. Call point 52 is for users who log into TPX with a password, passphrase, or pass code. Existing call point 48 is for users who log into TPX with a lock word. For more information, see Signon and Signoff Exit.
This enhancement is necessary because the LOCK/UNLOCK code structure was modified to work with a greater than 8-character password such as a passphrase or an RSA token.
5) Set up PassTickets for all of your applications before implementing MFA.
How to set up TPX to work with Pass Tickets in RACF
6) Create the ACL for auto signon to the application in your ACL library