Book description
This IBM Redbooks publication describes the implementation of RACF® in z/OS® Version 1 Release 8. This release continues to deliver industry leadership for security. Improvements have been introduced to further enhance the security-rich environment z/OS users rely on. These enhancements include:
- RACF support for virtual key rings to treat the collection of all the certificates owned by one user ID, including the SITE and CERTAUTH reserved user IDs, as an independent key ring. The use of the CERTAUTH virtual key ring will help to eliminate the need to manually create multiple real key rings for SSL-enabled z/OS client applications such as FTP.
- RACF template extensions allow templates to expand beyond their current 4K size.
- RACF supports the use of passwords longer than eight characters, now called password phrases.
- The RACF access control module exit, DSNXRXAC, has changed substantially with DB2® version 9. A RACF administrators can now define a security rule before an object is created and preserve the rule for a dropped object. In addition, RACF general resources for member and group profiles can be used by an installation to protect multiple DB2 resources with a single RACF profile.
- A new parameter on the IRRUT200 utility tells the utility to
activate the backup data set printed to as output. This is
accomplished by the utility internally issuing an RVARY ACTIVE for
the backup data set after the copy is complete. IRRUT200 and
IRRUT400 utilities now check whether their output data sets are
active primary or backup RACF data sets on this system.
New RACF health checks are introduced.
- RACF in z/OS V1R8 provides a solution to some functional gaps in the way that change logging of RACF profile updates were reflected in z/OS LDAP, and an enhancement is made to LISTUSER to demonstrate whether password enveloping is enabled for a user.
In addition to describing the new features, this book includes detailed steps for implementing these enhancements. It explains how to configure them for your installation and how to use them to increase the security of your environment.
Table of contents
- Notices
- Preface
- Chapter 1: RACF Version 1 Release 8
-
Chapter 2: Password phrase
- Password phrase benefits
- Password phrase and password
- How the password phrase works
- RACF commands and password phrase
- RACF remote sharing facility (RRSF)
- Password phrase and SETROPTS PASSWORD options
- Password phrase auditing
- Protected user IDs and password phrase
- Providing the ability to reset password phrases
- RACF utilities changes
- New and changed RACF messages
- Chapter 3: Availability improvements for IRRUT200 and IRRUT400
- Chapter 4: RACF and the DB2 access control module
- Chapter 5: RACF virtual key ring support
- Chapter 6: PKI Services
-
Chapter 7: RACF health checks
-
IBM Health Checker for z/OS
- Health checker overview
- Flow of IBM Health Checker for z/OS
- Security of IBM Health Checker for z/OS
- User interface to manage checks
- Using SDSF panels
- Using (E)JES panels
- Health Checker for z/OS commands via MODIFY command
- HZSPRMxx parmlib member and policies
- Policy statements
- Categories to manage and display information
- Criteria for the checks
- Common features of all RACF checks
- New RACF checks
- Enhanced RACF checks
-
IBM Health Checker for z/OS
- Chapter 8: LDAP change logging
- Chapter 9: Template and profile extensions
- Related publications
- Index (1/2)
- Index (2/2)
- Back cover
Product information
- Title: z/OS Version 1 Release 8 RACF Implementation
- Author(s):
- Release date: February 2007
- Publisher(s): IBM Redbooks
- ISBN: None
You might also like
book
Microsoft® PowerPivot for Excel® 2010
This book introduces PowerPivot in Excel 2010 to power users and data analysts who want to …
book
IBM z/OS V2R2: JES2, JES3, and SDSF
This IBM® Redbooks® publication helps you to become familiar with the technical changes that were introduced …
book
IBM z/OS V2R2: Diagnostics
This IBM® Redbooks® publication helps you to become familiar with the technical changes that were introduced …
book
AIX Fast Connect for AIX Version 3.1 Guide
Fast Connect for AIX, announced with AIX 4.3.2, was IBM's first step to let PCs take …