Re: Superuser Creation like IBMUSER
In [EMAIL PROTECTED], on 08/21/2006 at 02:29 AM, Brian Westerman [EMAIL PROTECTED] said: Personally I think that IBMUSER is one of the first ID's that should be removed after a new system installation, You don't want to do that; search the archives for why. -- Shmuel (Seymour J.) Metz, SysProg and JOAT ISO position; see http://patriot.net/~shmuel/resume/brief.html We don't care. We don't have to care, we're Congress. (S877: The Shut up and Eat Your spam act of 2003) -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html
Re: Superuser Creation like IBMUSER
In order to have another user have the same access capabilitites as the default (IBM deleivered with a new install of z/os) IBMUSER, you would have to join it to all of the same groups as IBMUSER. You also would have to give it access to many of the facility class options as well. On top of that, you would need to permit the user to various TSO based resources. The default IBMUSER also has been given access to a SH*Tload of dataset rules. I don't think that (as a rule) that rules should be written to an individual, only to groups. It will make life much easier for everyone, especially at a site that has a lot of personnel movement. Is there something specific that you want this new user to do? There really isn't anything special about IBMUSER itself, it just is a default that IBM and a lot of site (which really should not, but do any way), have given a lot of default resource access to. It's much better to create a group, (say SYSTEMS) and then give all of the permissions and resource access to that group, so that if you add a new systems programmer loose the main systems programmer, you don't have to make a whole lot of individual changes. Personally I think that IBMUSER is one of the first ID's that should be removed after a new system installation, there are too many sites that keep that ID around, and it's a security problem waiting to happen. -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html
Re: Superuser Creation like IBMUSER
snip Hi... Is it possible to create superuser like IBMUSER. I hav created user ABC with all SPEICAL OPERATIONS , AUDITOR privileges. Further, I have set the userid ABC omvs id as 0 same as tht of IBMUSER. Still I am not able to get full access to ISMF PRIMARY OPTION MENU - DFSMS V2R10 and not able to do Storage Admin functions like editing ACS routines , CDS activation .. Storage Group Administration anyone has any idea what all access rights I should assign to this new user so as to make it as superuser. --unsnip--- You need to look at the various STGADMIN profiles in RACF. --- [This E-mail has been scanned for viruses by the YourNet Connection Virus system] [For more information, please go to http://www.ync.net/YourMAIL] -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html
Superuser Creation like IBMUSER
Hi... Is it possible to create superuser like IBMUSER. I hav created user ABC with all SPEICAL OPERATIONS , AUDITOR privileges. Further, I have set the userid ABC omvs id as 0 same as tht of IBMUSER. Still I am not able to get full access to ISMF PRIMARY OPTION MENU - DFSMS V2R10 and not able to do Storage Admin functions like editing ACS routines , CDS activation .. Storage Group Administration anyone has any idea what all access rights I should assign to this new user so as to make it as superuser. Jacky -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html
Re: Superuser Creation like IBMUSER
On Sun, 20 Aug 2006 18:34:43 +0530, Jacky Bright [EMAIL PROTECTED] wrote: Hi... Is it possible to create superuser like IBMUSER. I hav created user ABC with all SPEICAL OPERATIONS , AUDITOR privileges. Further, I have set the userid ABC omvs id as 0 same as tht of IBMUSER. Still I am not able to get full access to ISMF PRIMARY OPTION MENU - DFSMS V2R10 and not able to do Storage Admin functions like editing ACS routines , CDS activation .. Storage Group Administration anyone has any idea what all access rights I should assign to this new user so as to make it as superuser. Jacky, In ISMF, do the following: - Select Option 0 (ISMF Profile) - Select Option 0 (User Mode Selection) - Select Option 1 (Storage Administrator) This should then give you what you want. You may need to exit out of ISMF completely for the change to take effect. Hope this helps Roger -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html
Re: Superuser Creation like IBMUSER
In [EMAIL PROTECTED], on 08/20/2006 at 06:34 PM, Jacky Bright [EMAIL PROTECTED] said: Is it possible to create superuser like IBMUSER. I'm not sure what you mean by superuser. IBMUSER is not root and does not automatically have all privileges. z/OS does not use the Unix 2-level (root and everybody else) security model. Privileges are controlled by access control lists (ACL's). -- Shmuel (Seymour J.) Metz, SysProg and JOAT ISO position; see http://patriot.net/~shmuel/resume/brief.html We don't care. We don't have to care, we're Congress. (S877: The Shut up and Eat Your spam act of 2003) -- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html