Setting Up CICS FCT Security

book

Article ID: 51214

calendar_today

Updated On:

Products

CA Cleanup CA Datacom - DB CA Datacom CA Datacom - AD CA Datacom - Server CA CIS CA Common Services for z/OS CA 90s Services CA Database Management Solutions for DB2 for z/OS CA Common Product Services Component CA Common Services CA Datacom/AD CA ecoMeter Server Component FOC CA Easytrieve Report Generator for Common Services CA Infocai Maintenance CA IPC Unicenter CA-JCLCheck Common Component CA Mainframe VM Product Manager CA Chorus Software Manager CA On Demand Portal CA Service Desk Manager - Unified Self Service CA PAM Client for Linux for zSeries CA Mainframe Connector for Linux on System z CA Graphical Management Interface CA Web Administrator for Top Secret CA CA- Xpertware CA Top Secret CA Top Secret - LDAP CA Top Secret - VSE

Issue/Introduction

 

Introduction:

 

How do you setup FCT security in a particular CICS region without affecting other CICS running within the same CPU/LPAR?

What is the impact of CA Top Secret CICS facility parameter RES/NORES and RESSEC=YES.

 

Solution:

 

If using FACMATRX=NO, the CICS SIT parameters control the CICS security including the RESSEC parameter on the PCT definitions.

To secure FCTs (DDNAME):

  • Set XFCT SIT parameter to XFCT=YES
  • and in the PCT RESSEC (YES)
  • DSNCHECK CICS facility control option must be set to NO.

Only the CICS regions with the CICS SIT parameters set, will be impacted.

If using FACMATRX(YES), CICS security is controlled by the CA Top Secret CICS FACILITY control options (XFCT, XPCT, XPPT?etc) instead of the CICS SIT parameters.

Please be careful when making changes to any of the CA Top Secret CICS FACILITY control options. All CICS regions sharing the same FACILITY name will be impacted by any changes to the CA Top Secret CICS FACILITY control options.

 

Additional Information:

 

 

 

The changes can be done with TSS MODI command.

To keep the changes permanent, please make the changes in your CA Top Secret parameter file member TSSPARM0 with CA Top Secret r15.0

With CA Top Secret r16.0, if you use the new control option FACSTOR(YES) you don't need to update your TSSPARM0, because the FACILITY is stored

and automatically updated within the VSAM companion file. 

 

For Ca Top Secret r16.0 go to docops.ca.com site; signon; choose your product CA Top Secret for z/OS - 16.0; click on "using" link; click on

 

"Specifying Control Options to Modify Your Security Environment" for more details about the FACSTOR() control option.

 

 

Environment

Release: TOPSEC00200-15-Top Secret-Security
Component: