> -----Original Message-----
> From: Linux on 390 Port [mailto:[EMAIL PROTECTED] On 
> Behalf Of Alan Altmark
> Sent: Thursday, January 10, 2008 1:07 PM
> To: [email protected]
> Subject: Re: Console Server equivalent for z/VM
> 
> I'm not sure I understand the learning curve problem.
> 
> 1. Telnet to the VM host (linemode is ok if you don't want 3270 stuff)
> 2. Enter LOGON userid BY myid and then your password
> 3. Make changes using Linux linemode toolset
> 

Is there an alternative to Telnet as due to PCI issues all non secure
access is supposed to be disabled - this means Telnet (our z/OS TN3270
is done over SSL due to this) ?

> If two logons is one too many, get rid of the authentication prompt in
> Linux for the console.
> 

I'm trying to persuade them that this is acceptable.


> You can change the user's VM password to NOPASS, enabling 
> unauthenticated
> access to the virtual machine console.  But before you do 
> that,  I suggest
> removing all CP commands (except DISCONNECT) from the user.  Otherwise
> anyone could walk up and destroy, plunder, or corrupt the 
> virtual machine.
>  CP commands would be limited to those issued in the CP 
> directory when the
> user logs on.  Of course, the issue of accessing the mainframe and
> entering the userid (if not the password) is still very much present.
> 
> If the guest's network connections are disabled, then there 
> is no VT220
> access to the guest except via the HMC's integrated VT220 
> console.  Only
> one guest at a time can use the VT220 console.
> 
> Alan Altmark
> z/VM Development
> IBM Endicott

The issue is more along the lines of user ID maintaince in RACF and a
mind set I refer to in my reply to Mark.
Unfortunately access to the HMC is even more restricted as I can't
control access at the lpar level and we are no about to allow the chance
of a unix admin  doing something to the z/OS side of the mainframe.

I need to look at the VT220 support more, but would love it if there was
a VM server that could do the function of the HMC VT220 in the same
fashion.

"Email Firewall" made the following annotations.
------------------------------------------------------------------------------

Warning: 
All e-mail sent to this address will be received by the corporate e-mail 
system, and is subject to archival and review by someone other than the 
recipient.  This e-mail may contain proprietary information and is intended 
only for the use of the intended recipient(s).  If the reader of this message 
is not the intended recipient(s), you are notified that you have received this 
message in error and that any review, dissemination, distribution or copying of 
this message is strictly prohibited.  If you have received this message in 
error, please notify the sender immediately.   
 
==============================================================================

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to