11.01.2013 Views

ABCs of z/OS System Programming Volume 3 - IBM Redbooks

ABCs of z/OS System Programming Volume 3 - IBM Redbooks

ABCs of z/OS System Programming Volume 3 - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Because APF authorization is established at the job step task level, access method services<br />

is not authorized if invoked by an unauthorized application or terminal monitor program.<br />

RACF authorization checking<br />

RACF provides a s<strong>of</strong>tware access control measure you can use in addition to or instead <strong>of</strong><br />

passwords. RACF protection and password protection can coexist for the same data set.<br />

To open a catalog as a data set, you must have ALTER authority and APF authorization.<br />

When defining an SMS-managed data set, the system only checks to make sure the user has<br />

authority to the data set name and SMS classes and groups. The system selects the<br />

appropriate catalog, without checking the user's authority to the catalog. You can define a<br />

data set if you have ALTER or OPERATIONS authority to the applicable data set pr<strong>of</strong>ile.<br />

Deleting any type <strong>of</strong> RACF-protected entry from a RACF-protected catalog requires ALTER<br />

authorization to the catalog or to the data set pr<strong>of</strong>ile protecting the entry being deleted. If a<br />

non-VSAM data set is SMS-managed, RACF does not check for DASDVOL authority. If a<br />

non-VSAM, non-SMS-managed data set is being scratched, DASDVOL authority is also<br />

checked.<br />

For ALTER RENAME, the user is required to have the following two types <strong>of</strong> authority:<br />

► ALTER authority to either the data set or the catalog<br />

► ALTER authority to the new name (generic pr<strong>of</strong>ile) or CREATE authority to the group<br />

Be sure that RACF pr<strong>of</strong>iles are correct after you use REPRO MERGECAT or CNVTCAT on a<br />

catalog that uses RACF pr<strong>of</strong>iles. If the target and source catalogs are on the same volume,<br />

the RACF pr<strong>of</strong>iles remain unchanged.<br />

Tape data sets defined in an integrated catalog facility catalog can be protected by:<br />

► Controlling access to the tape volumes<br />

► Controlling access to the individual data sets on the tape volumes<br />

Pr<strong>of</strong>iles<br />

To control the ability to perform functions associated with storage management, define<br />

pr<strong>of</strong>iles in the FACILITY class whose pr<strong>of</strong>ile names begin with STGADMIN (storage<br />

administration). For a complete list <strong>of</strong> STGADMIN pr<strong>of</strong>iles, see z/<strong>OS</strong> DFSMSdfp Storage<br />

Administration Reference, SC26-7402. Examples <strong>of</strong> pr<strong>of</strong>iles include:<br />

STGADMIN.IDC.DIAGN<strong>OS</strong>E.CATALOG<br />

STGADMIN.IDC.DIAGN<strong>OS</strong>E.VVDS<br />

STGADMIN.IDC.EXAMINE.DATASET<br />

360 <strong>ABCs</strong> <strong>of</strong> z/<strong>OS</strong> <strong>System</strong> <strong>Programming</strong> <strong>Volume</strong> 3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!