When creating a userid in ACF2 ..how to add VM parameters?

All about SAF, RACF, encryption, Firewall, Risk assessment and integrity concepts
parthiban
Posts: 66
Joined: Mon Oct 20, 2008 7:54 pm
Skillset: REXX,JCL,RACF
Referer: Google
Location: Bangalore-India
Contact:

When creating a userid in ACF2 ..how to add VM parameters?

Postby parthiban » Wed Mar 17, 2010 11:11 pm

Hello all,

When creating a userid in ACF2 ..how to add VM parameters?



Thanks.
parthiban
Parthiban jayaraman
mainframe rexxer,
Banglore

User avatar
dick scherrer
Global moderator
Posts: 6268
Joined: Sat Jun 09, 2007 8:58 am

Re: When creating a userid in ACF2 ..how to add VM parameters?

Postby dick scherrer » Thu Mar 18, 2010 2:55 am

Hello,

What is a "VM parameter"?
Hope this helps,
d.sch.

enrico-sorichetti
Global moderator
Posts: 3006
Joined: Fri Apr 18, 2008 11:25 pm
Skillset: tso,rexx,assembler,pl/i,storage,mvs,os/390,z/os,
Referer: www.ibmmainframes.com

Re: When creating a userid in ACF2 ..how to add VM parameters?

Postby enrico-sorichetti » Fri Mar 19, 2010 1:13 pm

what does the ACF manual say ?
cheers
enrico
When I tell somebody to RTFM or STFW I usually have the page open in another tab/window of my browser,
so that I am sure that the information requested can be reached with a very small effort

parthiban
Posts: 66
Joined: Mon Oct 20, 2008 7:54 pm
Skillset: REXX,JCL,RACF
Referer: Google
Location: Bangalore-India
Contact:

Re: When creating a userid in ACF2 ..how to add VM parameters?

Postby parthiban » Mon Mar 22, 2010 3:31 pm

Hi ,

VM parameters means VM SYSTEMs?
Parthiban jayaraman
mainframe rexxer,
Banglore

enrico-sorichetti
Global moderator
Posts: 3006
Joined: Fri Apr 18, 2008 11:25 pm
Skillset: tso,rexx,assembler,pl/i,storage,mvs,os/390,z/os,
Referer: www.ibmmainframes.com

Re: When creating a userid in ACF2 ..how to add VM parameters?

Postby enrico-sorichetti » Mon Mar 22, 2010 6:49 pm

VM as in z/VM...
if this is the case how does the parameter/option relate to a z/OS environment ??
... remember these forums deal <only> with z/OS related issues
cheers
enrico
When I tell somebody to RTFM or STFW I usually have the page open in another tab/window of my browser,
so that I am sure that the information requested can be reached with a very small effort

steve-myers
Global moderator
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Skillset: Assembler, JCL, utilities
Referer: zos.efglobe.com

Re: When creating a userid in ACF2 ..how to add VM parameters?

Postby steve-myers » Sat Jun 12, 2010 6:23 am

I used to be a Top Secret DCA (that's the lowest level of enhanced authority in Top Secret) in a shop that had both z/OS and z/VM systems. As far as I know the big 3 security packages all have versions for both z/OS and z/VM. This was certainly true for Top Secret. In my shop, there were a number of security islands, some z/OS and some z/VM, but Top Secret shipped updates on one system to most of the other islands. I did most of my updates on a z/OS system, including z/VM updates, with the expectation the update would be sent to the other islands.

I expect ACF2 works about the same way, but I don't know this to be a fact.

So, Top Secret did keep z/VM related data in it z/OS data base. I think RACF physically shares its database with z/VM systems, but I don't know this for a fact.

Since ACF2 uses VSAM for its data bases, and I think z/VM's support for VSAM is pretty primitive, I'm not sure sharing data bases between z/OS and z/VM is reasonable with the z/VM version of ACF2.

Top Secret's sharing by replicating data to other islands usually worked OK, though I would have to logon to the other islands to confirm the update took on the alternate system. At least once the update didn't take because the island was down when I did my update on the "master" system, more often it didn't take because of subtle differences between the "master" system and the other islands.

Most password changes took place on the system running the global session manager, a security island I did not have access to. Once (and only once) in 8+ years a password change for my ID did not propagate to what I regarded as the "master" system, and I had to scramble to fix it.


  • Similar Topics
    Replies
    Views
    Last post