CA Top Secret Shows *BYPASS* Instead Of +MASTER+ For JESSPOOL Resource.

book

Article ID: 50851

calendar_today

Updated On:

Products

CA Cleanup CA Datacom CA DATACOM - AD CA CIS CA Common Services for z/OS CA 90s Services CA Database Management Solutions for DB2 for z/OS CA Common Product Services Component CA Common Services CA Datacom/AD CA ecoMeter Server Component FOC CA Easytrieve Report Generator for Common Services CA Infocai Maintenance CA IPC Unicenter CA-JCLCheck Common Component CA Mainframe VM Product Manager CA Chorus Software Manager CA On Demand Portal CA Service Desk Manager - Unified Self Service CA PAM Client for Linux for zSeries CA Mainframe Connector for Linux on System z CA Graphical Management Interface CA Web Administrator for Top Secret CA CA- Xpertware CA Top Secret CA Top Secret - LDAP CA Top Secret - VSE

Issue/Introduction

Description:

For SDSF operation, IBM SDSF Operation and Customization Guide says that users need access to JESSPOOL resource locnode.+MASTER+.SYSLOG.SYSTEM.sysname.

But, with CA Top Secret acids, they need access to locnode.*BYPASS*.SYSLOG.SYSTEM.sysname.

Solution:

The second qualifier in a JESSPOOL resource is the userid that owns the SYSOUT data being protected. With CA Top Secret, it is normally an acid name.

CA Top Secret usually does not allow ACEEs to be created for undefined users.

+MASTER+ is undefined in RACF, but RACF does allow ACEEs to be created for undefined users.

CA Top Secret makes a specific exception for userids starting with a '+' in a handful of FACILITYs, but CA Top Secret treats these as bypass users and uses a userid of *BYPASS* in the ACEE that is created.

When a JESSPOOL resource name is constructed, it uses the userid from the ACEE. The *BYPASS* ACEE will result in a JESSPOOL resource owned by *BYPASS*.

You can use *BYPASS* in the PERMIT command, but CA Top Secret will interpret the '*'s as masking characters. For that reason, use +BYPASS+ in the PERMIT.

It's still a masking character, but there are fewer resource names that will match.

Changing the way CA Top Secret creates an ACEE in a situation where it is creating a bypass user to make the JESSPOOL resource name match like RACF
would require a major design change..

It is recommended to adjust the PERMIT command to the CA Top Secret form.

Environment

Release:
Component: AWAGNT