On Tue, 15 Dec 2009 11:51:51 -0600, Paul Gilmartin <[email protected]> wrote:

>Wouldn't that risk exist with the current IDCAMS ALIAS facility?
>Isn't SAF checking done on the actual (VTOC) data set name, not
>on the alias?
>

Correct, gil.  The alias has no relevance for security purposes.

His point about long names causing problems on tapes is, of course, true,
but that applies to any tape data set name longer than 17 characters, in the
absence of a tape manager or of RACF TAPEVOL profiles with TVTOCs.

-- 
Walt Farrell, CISSP
IBM STSM, z/OS Security Design

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to