09.12.2012 Views

Download PDF - IBM Redbooks

Download PDF - IBM Redbooks

Download PDF - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PASSWORD PROCESSING OPTIONS:<br />

PASSWORD CHANGE INTERVAL IS 90 DAYS.<br />

PASSWORD MINIMUM CHANGE INTERVAL IS 0 DAYS.<br />

MIXED CASE PASSWORD SUPPORT IS IN EFFECT<br />

NO PASSWORD HISTORY BEING MAINTAINED.<br />

USERIDS NOT BEING AUTOMATICALLY REVOKED.<br />

PASSWORD EXPIRATION WARNING LEVEL IS 10 DAYS.<br />

NO INSTALLATION PASSWORD SYNTAX RULES ARE PRESENT.<br />

Figure 12-8 Password excerpt of the SETROPTS LIST command output<br />

Note: The use of mixed-case passwords on your z/OS systems needs to be<br />

very carefully planned. Instructing your users is of utmost importance to avoid<br />

confusion after having entered a new password. Falling back to<br />

NOMIXEDCASE has an even bigger impact, since all mixed-case passwords<br />

will need to be reset.<br />

12.4 Sync-to-OS thread update<br />

The Sync-To-OS thread security concept is unique to WebSphere Application<br />

Server on z/OS. It allows the current J2EE thread identity to be propagated to the<br />

OS thread for use by z/OS resource managers outside the scope of the J2EE<br />

container. It effectively sets the servant regions TCB level ACEE to the current<br />

JAAS principal. On other platforms this would always be the user ID that the EJB<br />

container is running under. In the case of WebSphere Application Server on<br />

z/OS, the user ID under which the servant region STC is running would be used<br />

to access back-end systems (also referred to Enterprise Information Systems, or<br />

EIS) or other resources on z/OS if the Sync-To-OS thread option is set to false.<br />

Prior to WebSphere V6.1, Sync-to-OS thread was controlled in two ways.<br />

► The WebSphere Application Server developer had to configure the<br />

application to declare that it needs to run with application Sync-to-OS thread.<br />

► The WebSphere Application Server administrator had to configure the<br />

application server to enable application Sync-to-OS thread allowed.<br />

What is new in Version 6.1<br />

Additional controls have been added to secure thread security and thread<br />

identity support. A new FACILITY class profile must be defined in order for<br />

Sync-to-OS thread to be allowed. The control region user ID need READ or<br />

CONTROL access to enable Sync-to-OS thread. With READ access, only<br />

444 Security in WebSphere Application Server Version 6.1 and J2EE 1.4 on z/OS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!