Hello, Troy.
Consider also give authority to individual userids, when justified. And
consider products self protection.
Example: DIRMAINT have his own mechanism to enable administrators
(AUTHUSER), RSCS have self protection for his commands, OPERATOR must be
managed by individuals defined into RTABLES, etc.,
For dangerous machines, use the LOGONBY option, enabling the individuals
to logon it, only when need. Example: Network (TCPIP) have the TCPMAINT
machine, RACF have AUDITOR, CP/CMS have MAINT. These machines  (MAINT,
AUDITOR, TCPMAINT) needs LOGONBY.
For the few powerful service machines, do not  enable them to logon
directly (TCPIP, RACFVM, OPERATOR): they must be managed by their partners
and must work disconnected. Or LOGONBY by a more restricted group, for
emergency only.
I know several customers that work this way, and they consider easy to
administer, after the first installation impact.
Regards,
______________________________________________
Clovis



From:
"George, Kevin A" <[email protected]>
To:
[email protected]
Date:
18/08/2011 14:19
Subject:
Re: RACF and sysprog ID
Sent by:
Linux on 390 Port <[email protected]>



On VM our SYSPROG users do not have any special RACF authority. We do have
LOGONBY access to all of the maintenance machines including MAINT and
TCPMAINT. This allows for any maintenance you may need to do. We also set
the VM privileges to ABCDEFG for those users which allows them to see and
control most things in VM.

-------------------------------------
Kevin George
U.S. Office of Personnel Management
1900 E Street NW
Room BH04L
Washington, DC 20415
(202) 606-1195 - Main
(202) 528-8215 - Cell
________________________________________
From: Linux on 390 Port [[email protected]] On Behalf Of Troy A
Slaughter [[email protected]]
Sent: Thursday, August 18, 2011 12:07 PM
To: [email protected]
Subject: RACF and sysprog ID

Hi all,

I'm trying to figure out the best way to define authority to a SYSPROG
group under RACF/VM.  I don't want SYSPROG members to have all authority
so I don't want to just add SPECIAL and OPERATION attributes to the group.
 But they should be able to perform system-wide list operations and such.
I also want them to have certain system display capabilities.  It seems
the only way to do that is via privilege classes.  If I'm right, it looks
like I will be doing a combination of RACF alterations to the SYSPROG
group as well as privilege class changes to the individual system IDs.

[cid:_2_0F36822C0F367E5800589D60862578F0]
_______________________________________________________________________________
Troy Slaughter | Software Consultant | Mainframe Platform Engineering
50 South Lasalle Street, LQ 11SE, Chicago, Illinois, 60603 | Phone
312-557-6322 | Cell 312-208-3735 | [email protected] <mailto:[email protected]>
Please visit northerntrust.com<http://www.northerntrust.com/>

CONFIDENTIALITY NOTICE: This communication is confidential, may be
privileged and is meant only for the intended recipient. If you are not
the intended recipient, please notify the sender ASAP and delete this
message from your system.

IRS CIRCULAR 230 NOTICE: To the extent that this message or any attachment
concerns tax matters, it is not intended to be used and cannot be used by
a taxpayer for the purpose of avoiding penalties that may be imposed by
law. For more information about this notice, see
http://www.northerntrust.com/circular230

P Please consider the environment before printing this e-mail.

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO LINUX-390 or
visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/




----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390
----------------------------------------------------------------------
For more information on Linux on System z, visit
http://wiki.linuxvm.org/

Reply via email to