Hello, Troy. Consider also give authority to individual userids, when justified. And consider products self protection. Example: DIRMAINT have his own mechanism to enable administrators (AUTHUSER), RSCS have self protection for his commands, OPERATOR must be managed by individuals defined into RTABLES, etc., For dangerous machines, use the LOGONBY option, enabling the individuals to logon it, only when need. Example: Network (TCPIP) have the TCPMAINT machine, RACF have AUDITOR, CP/CMS have MAINT. These machines (MAINT, AUDITOR, TCPMAINT) needs LOGONBY. For the few powerful service machines, do not enable them to logon directly (TCPIP, RACFVM, OPERATOR): they must be managed by their partners and must work disconnected. Or LOGONBY by a more restricted group, for emergency only. I know several customers that work this way, and they consider easy to administer, after the first installation impact. Regards, ______________________________________________ Clovis
From: "George, Kevin A" <[email protected]> To: [email protected] Date: 18/08/2011 14:19 Subject: Re: RACF and sysprog ID Sent by: Linux on 390 Port <[email protected]> On VM our SYSPROG users do not have any special RACF authority. We do have LOGONBY access to all of the maintenance machines including MAINT and TCPMAINT. This allows for any maintenance you may need to do. We also set the VM privileges to ABCDEFG for those users which allows them to see and control most things in VM. ------------------------------------- Kevin George U.S. Office of Personnel Management 1900 E Street NW Room BH04L Washington, DC 20415 (202) 606-1195 - Main (202) 528-8215 - Cell ________________________________________ From: Linux on 390 Port [[email protected]] On Behalf Of Troy A Slaughter [[email protected]] Sent: Thursday, August 18, 2011 12:07 PM To: [email protected] Subject: RACF and sysprog ID Hi all, I'm trying to figure out the best way to define authority to a SYSPROG group under RACF/VM. I don't want SYSPROG members to have all authority so I don't want to just add SPECIAL and OPERATION attributes to the group. But they should be able to perform system-wide list operations and such. I also want them to have certain system display capabilities. It seems the only way to do that is via privilege classes. If I'm right, it looks like I will be doing a combination of RACF alterations to the SYSPROG group as well as privilege class changes to the individual system IDs. [cid:_2_0F36822C0F367E5800589D60862578F0] _______________________________________________________________________________ Troy Slaughter | Software Consultant | Mainframe Platform Engineering 50 South Lasalle Street, LQ 11SE, Chicago, Illinois, 60603 | Phone 312-557-6322 | Cell 312-208-3735 | [email protected] <mailto:[email protected]> Please visit northerntrust.com<http://www.northerntrust.com/> CONFIDENTIALITY NOTICE: This communication is confidential, may be privileged and is meant only for the intended recipient. If you are not the intended recipient, please notify the sender ASAP and delete this message from your system. IRS CIRCULAR 230 NOTICE: To the extent that this message or any attachment concerns tax matters, it is not intended to be used and cannot be used by a taxpayer for the purpose of avoiding penalties that may be imposed by law. For more information about this notice, see http://www.northerntrust.com/circular230 P Please consider the environment before printing this e-mail. ---------------------------------------------------------------------- For LINUX-390 subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO LINUX-390 or visit http://www.marist.edu/htbin/wlvindex?LINUX-390 ---------------------------------------------------------------------- For more information on Linux on System z, visit http://wiki.linuxvm.org/ ---------------------------------------------------------------------- For LINUX-390 subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO LINUX-390 or visit http://www.marist.edu/htbin/wlvindex?LINUX-390 ---------------------------------------------------------------------- For more information on Linux on System z, visit http://wiki.linuxvm.org/
