Security Server (RACF)
Planning:Installation and Migration
GC28-1920-03
OS/390IBM
Security Server (RACF)
Planning:Installation and Migration
GC28-1920-03
Note
Before using this information and the product it supports, be sure to read the general information under “Notices” on page vii.
Fourth Edition, September 1997
This is a major revision of GC28-1920-02.
This edition applies to Version 2 Release 4 of OS/390 (5647-A01) and to all subsequent releases and modifications until otherwise
indicated in new editions.
Order publications through your IBM representative or the IBM branch office serving your locality. Publications are not stocked at the
address below.
IBM welcomes your comments. A form for readers' comments may be provided at the back of this publication, or you may address
your comments to the following address:
International Business Machines Corporation
Department 55JA, Mail Station P384
522 South Road
Poughkeepsie, NY 12601-5400
United States of America
FAX (United States & Canada): 1+914+432-9405
FAX (Other Countries):
Your International Access Code +1+914+432-9405
IBMLink (United States customers only): KGNVMC(MHVRCFS)
IBM Mail Exchange: USIB6TC9 at IBMMAIL
Internet e-mail: mhvrcfs@vnet.ibm.com
World Wide Web: http://www.s390.ibm.com/os390
If you would like a reply, be sure to include your name, address, telephone number, or FAX number.
Make sure to include the following in your comment or note:
Title and order number of this book
Page number or topic related to your comment
When you send information to IBM, you grant IBM a nonexclusive right to use or distribute the information in any way it believes
appropriate without incurring any obligation to you.
Copyright International Business Machines Corporation 1994, 1997. All rights reserved.
Note to U.S. Government Users — Documentation related to restricted rights — Use, duplication or disclosure is subject to
restrictions set forth in GSA ADP Schedule Contract with IBM Corp.
12.Changes to SMF Records........................... 33
Copyright IBM Corp. 1994, 1997 v
viOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
Notices
References in this publication to IBM products, programs, or services do not imply
that IBM intends to make these available in all countries in which IBM operates.
Any reference to an IBM product, program, or service is not intended to state or
imply that only IBM's product, program, or service may be used. A functionally
equivalent product, program, or service which does not infringe on any of IBM's
intellectual property rights may be used instead of the IBM product, program, or
service. Evaluation and verification of operation in conjunction with other products,
programs, or services, except those expressly designated by IBM, is the user's
responsibility.
IBM may have patents or pending patent applications covering subject matter in
this document. The furnishing of this document does not give you any license to
these patents. You can send license inquiries, in writing, to:
IBM Director of Licensing
IBM Corporation
500 Columbus Avenue
Thornwood, NY 10594
USA
Licensees of this program who wish to have information about it for the purpose of
enabling: (i) the exchange of information between independently created programs
and other programs (including this one) and (ii) the mutual use of the information
which has been exchanged, should contact:
IBM Corporation
Mail Station P300
522 South Road
Poughkeepsie, NY 12601-5400
USA
Attention: Information Request
Such information may be available, subject to appropriate terms and conditions,
including in some cases, payment of a fee.
Copyright IBM Corp. 1994, 1997 vii
viiiOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
Trademarks
The following terms are trademarks of the IBM Corporation in the United States or
other countries or both:
UNIX is a registered trademark in the United States and other countries licensed
exclusively through X/Open Company Limited.
Windows is a trademark of Microsoft Corporation.
Other company, product, and service names, which may be denoted by a double
asterisk (**), may be trademarks or service marks of others.
Copyright IBM Corp. 1994, 1997 ix
xOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
About This Book
This book contains information about the Resource Access Control Facility (RACF),
which is part of the OS/390 Security Server. The Security Server has two
components:
RACF
OpenEdition DCE Security Server
For information about the OpenEdition DCE Security Server, see the publications
related to that component.
This book provides information to guide you through the migration process from
OS/390 Release 3 Security Server (RACF) or RACF to OS/390 Release 4 Security
Server (RACF).
The purpose of this book is to ensure an orderly transition to a new RACF release.
It is
release prior to Security Server (RACF) Release 3. First-time RACF customers
should read
directory shipped with the product when they are ready to install the product.
not
intended for customers installing RACF for the first time or installing a
OS/390 Security Server (RACF) Introduction
and use the program
Who Should Use This Book
This book is intended for experienced system programmers responsible for
migrating from OS/390 Release 3 Security Server (RACF) to OS/390 Release 4
Security Server (RACF). This book assumes you have knowledge of OS/390
Release 3 Security Server (RACF).
If you are migrating from a RACF 2.2, or earlier, or from an OS/390 Security Server
release prior to OS/390 Release 3, you should also read previous versions of this
book, as described in “Migration Paths for OS/390 Release 4 Security Server
(RACF)” on page 21.
How to Use This Book
This book is organized in the following order:
Chapter 1, “Planning for Migration” on page 1, provides information to help you
plan your installation's migration to the new release of RACF.
Chapter 2, “Release Overview” on page 5, provides an overview of support in
the new release.
Chapter 3, “Summary of Changes to RACF Components for OS/390 Release
4” on page 11, lists specific new and changed support for the new release.
Chapter 4, “Planning Considerations” on page 21, describes high-level
migration considerations for customers upgrading to the new release of RACF
from previous levels of RACF.
Chapter 5, “Installation Considerations” on page 25, highlights information
about installing the new release of RACF.
Copyright IBM Corp. 1994, 1997 xi
Chapter 6, “Customization Considerations” on page 29, highlights information
about customizing function to take advantage of new support after the new
release of RACF is installed.
Chapter 7, “Administration Considerations” on page 31, summarizes changes
to administration procedures for the new release of RACF.
Chapter 8, “Auditing Considerations” on page 33, summarizes changes to
auditing procedures for the new release of RACF.
Chapter 9, “Application Development Considerations” on page 35, identifies
changes in the new release of RACF that might require changes to an
installation's existing programs.
Chapter 10, “General User Considerations” on page 37, summarizes new
support that might affect general user procedures.
Where to Find More Information
Where necessary, this book references information in other books. For complete
titles and order numbers for all products that are part of OS/390, see
Information Roadmap
.
OS/390
Softcopy Publications
The OS/390 Security Server (RACF) library is available on the following CD-ROMs.
The CD-ROM collections include the IBM Library Reader, a program that enables
customers to read the softcopy books.
The
The
The
OS/390 Security Server (RACF) Information Package
This softcopy collection kit contains the OS/390 Security Server (RACF) library.
It also contains the RACF/MVS Version 2 product libraries, the RACF/VM 1.10
product library, product books from the OS/390 and VM collections,
International Technical Support Organization (ITSO) books, and Washington
System Center (WSC) books that contain substantial amounts of information
related to RACF. The kit does not contain any licensed publications. By using
this CD-ROM, you have access to RACF-related information from IBM products
such as OS/390, VM, CICS, and NetView without maintaining shelves of
hardcopy documentation or handling multiple CD-ROMs. To get more
information on the
the advertisement at the back of the book.
OS/390 Collection Kit
This softcopy collection contains a set of OS/390 and related product books.
This kit contains unlicensed books.
OS/390 Security Server (RACF) Information Package
, SK2T-6700
Online Library Omnibus Edition MVS Collection Kit,
This softcopy collection contains a set of key MVS and MVS-related product
books. It also includes the RACF Version 2 product libraries.
Server (RACF) Messages and Codes
is also available as part of
Productivity Edition Messages and Codes Collection,
, SK2T-2180
, see
SK2T-0710
OS/390 Security
Online Library
SK2T-2068.
xiiOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
RACF Courses
The following RACF classroom courses are also available:
Effective RACF Administration,
MVS/ESA RACF Security Topics,
Implementing RACF Security for CICS/ESA,
IBM provides a variety of educational offerings for RACF. For more information on
classroom courses and other offerings, see your IBM representative,
Mainframe Training Solutions
(1-800-426-8322).
IBM Systems Center Publications
IBM systems centers produce “red” and “orange” books that can be helpful in
setting up and using RACF.
These books have not been subjected to any formal review nor have they been
checked for technical accuracy, but they represent current product understanding
(at the time of their publication) and provide valuable information on a wide range
of RACF topics. They are not shipped with RACF. You must order them
separately. A selected list of these books follows:
H3927
H3918
H3992
IBM
, GR28-5467, or call 1-800-IBM-TEACH
|
Systems Security Publications Bibliography,
Elements of Security: RACF Overview - Student Notes,
Elements of Security: RACF Installation - Student Notes,
Elements of Security: RACF Advanced Topics - Student Notes,
RACF Version 2 Release 2 Technical Presentation Guide,
RACF Version 2 Release 2 Installation and Implementation Guide,
Enhanced Auditing Using the RACF SMF Data Unload Utility,
RACF Macros and Exit Coding,
RACF Support for Open Systems Technical Presentation Guide,
DFSMS and RACF Usage Considerations,
Introduction to System and Network Security: Considerations, Options, and
Techniques,
Network Security Involving the NetView Family of Products,
System/390 MVS Sysplex Hardware and Software Migration,
Secured Single Signon in a Client/Server Environment,
Tutorial: Options for Tuning RACF,
GG24-3451
GG24-3984
GG22-9396
OS/390 Security Server Audit Tool and Report Application
G320-9279
GG24-3970
GG24-3971
GG24-3972
GG24-2539
SG24-4580
GG24-4453
GG26-2005
GG24-3378
GG24-3524
GC28-1210
GG24-4282
, SG24-4820
Other books are available, but they are not included in this list, either because the
information they present has been incorporated into IBM product manuals, or
because their technical content is outdated.
About This Bookxiii
Other Sources of Information
IBM provides customer-accessible discussion areas where RACF may be
discussed by customer and IBM participants. Other information is available through
the Internet.
IBM Discussion Areas
Two discussion areas provided by IBM are the MVSRACF discussion and the
SECURITY discussion.
MVSRACF
MVSRACF is available to customers through IBM's TalkLink offering. To access
MVSRACF from TalkLink:
1. Select S390 (the S/390 Developers' Association).
2. Use the fastpath keyword: MVSRACF.
SECURITY
SECURITY is available to customers through IBM's DialIBM offering, which
may be known by other names in various countries. To access SECURITY:
1. Use the CONFER fastpath option.
2. Select the SECURITY CFORUM.
Contact your IBM representative for information on TalkLink, DialIBM, or equivalent
offerings for your country and for more information on the availability of the
MVSRACF and SECURITY discussions.
Internet Sources
The following resources are available through the Internet:
RACF home page
You can visit the RACF home page on the World Wide Web using this address:
http://www.s39ð.ibm.com/products/racf/racfhp.html
or
http://www.s39ð.ibm.com/racf
RACF-L discussion list
Customers and IBM participants may also discuss RACF on the RACF-L
discussion list. RACF-L is not operated or sponsored by IBM; it is run by the
University of Georgia.
To subscribe to the RACF-L discussion, so you can receive postings, send a
note to:
listserv@uga.cc.uga.edu
Include the following line in the body of the note, substituting your first name
and last name as indicated:
subscribe racf-l first_name last_name
To post a question or response to RACF-L, send a note to:
racf-l@uga.cc.uga.edu
Include an appropriate Subject: line.
Sample code
xivOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
You can get sample code, internally-developed tools, and exits to help you use
RACF. All this code works in our environment, at the time we make it available,
but is not officially supported. Each tool or sample has a README file that
describes the tool or sample and any restrictions on its use.
The simplest way to reach this code is through the RACF home page. From the
home page, click on System/390 FTP Servers under the topic, “RACF Sample
Materials.”
The code is also available from lscftp.pok.ibm.com through anonymous ftp.
To get access:
1. Log in as user anonymous.
2. Change the directory (cd) to /pub/racf/mvs to find the subdirectories that
contain the sample code. We'll post an announcement on RACF-L,
MVSRACF, and SECURITY CFORUM whenever we add anything.
Restrictions
Because the sample code and tools are not officially supported,
There are no guaranteed enhancements.
No APARs can be accepted.
The name and availability of the ftp server may change in the future. We'll
post an announcement on RACF-L, MVSRACF, and SECURITY CFORUM
if this happens.
However, even with these restrictions, it should be useful for you to have
access to this code.
To Request Copies of IBM Publications
Direct your request for copies of any IBM publication to your IBM representative or
to the IBM branch office serving your locality.
There is also a toll-free customer support number (1-800-879-2755) available
Monday through Friday from 6:30 a.m. through 5:00 p.m. Mountain Time. You can
use this number to:
Order or inquire about IBM publications
Resolve any software manufacturing or delivery concerns
Activate the Program Reorder Form to provide faster and more convenient
ordering of software updates
See the advertisement at the back of the book for information about the
Security Server (RACF) Information Package.
OS/390
About This Bookxv
xviOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
Summary of Changes
|Summary of Changes
|for GC28-1920-03
|OS/390 Version 2 Release 4
|This book contains primarily new information for OS/390 Version 2 Release 4
|Security Server (RACF). When any information appeared in an earlier release, the
|information that is new is indicated by a vertical line to the left of the change.
Summary of Changes
for GC28-1920-02
OS/390 Release 3
This book contains new information for OS/390 Release 3 Security Server (RACF).
Summary of Changes
for GC28-1920-01
OS/390 Release 2
This book contains new information for OS/390 Release 2 Security Server (RACF).
Summary of Changes
for GC28-1920-00
OS/390 Release 1
This book contains information previously presented in
and Migration
This book includes terminology, maintenance, and editorial changes.
, GC23-3736, which supports RACF Version 2 Release 2.
RACF Planning: Installation
Copyright IBM Corp. 1994, 1997 xvii
xviiiOS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
Chapter 1.Planning for Migration
This chapter provides information to help you plan your installation's migration to
the new release of OS/390 Security Server (RACF). Before attempting to migrate,
you should define a plan to ensure a smooth and orderly transition. A well
thought-out and documented migration plan can help minimize any interruption of
service. Your migration plan should address such topics as:
Identifying which required and optional products are needed
Evaluating new and changed functions
Evaluating how incompatibilities affect your installation
Defining necessary changes to:
Defining education requirements for operators and end users
Preparing your staff and end users for migration, if necessary
Acquiring and installing the latest service level of RACF for maintenance
The content and extent of a migration plan can vary significantly from installation to
installation. To successfully migrate to a new release of RACF, you should start by
installing and stabilizing the new RACF release without activating the new functions
provided. Installing the new RACF release without initially exploiting new functions
allows you to maintain a stable RACF environment. The program directory shipped
with the new OS/390 release gives detailed information about the correct software
required for installation.
When defining your installation's migration plan, you should consider the following:
Migration
Installation
Customization
Administration
Auditing
Operation
Application development
General users
Migration Planning Considerations
Installations planning to migrate to a new release of RACF must consider high-level
support requirements such as machine and programming restrictions, migration
paths, and program compatibility.
For more information, see Chapter 4, “Planning Considerations” on page 21.
Copyright IBM Corp. 1994, 1997 1
Installation Considerations
Before installing a new release of RACF, you must determine what updates are
needed for IBM-supplied products, system libraries, and non-IBM products.
(Procedures for installing RACF are described in the program directory shipped with
OS/390, not in this book.)
Be sure you include the following steps when planning your pre-installation
activities:
Obtain and install any required program temporary fixes (PTFs) or updated
versions of the operating system.
Call the IBM Software Support Center to obtain the preventive service planning
(PSP) upgrade for RACF. This provides the most current information on PTFs
for RACF. Have RETAIN checked again just before testing RACF. Information
for requesting the PSP upgrade can be found in the program directory.
Although the program directory contains a list of the required PTFs, the most
current information is available from the support center.
Contact programmers responsible for updating programs.
Verify that your installation's programs will continue to run, and, if necessary,
make changes to ensure compatibility with the new release.
For more information, see Chapter 5, “Installation Considerations” on page 25.
Customization Considerations
In order for RACF to meet the specific requirements of your installation, you can
customize function to take advantage of new support after the product is installed.
For example, you can tailor RACF through the use of installation exit routines, class
descriptor table (CDT) support, or options to improve performance. This book lists
changes to RACF that might require the installation to tailor the product, either to
ensure that RACF runs as before or to accommodate new security controls that an
installation requires.
For more information, see Chapter 6, “Customization Considerations” on page 29.
Administration Considerations
Security administrators must be aware of how changes introduced by a new
product release can affect an installation's data processing resources. Changes to
real and virtual storage requirements, performance, security, and integrity are of
interest to security administrators or to system programmers who are responsible
for making decisions about the computing system resources used with a program.
For more information, see Chapter 7, “Administration Considerations” on page 31.
2OS/390 V2R4.0 Security Server (RACF) Planning: Installation and Migration
Auditing Considerations
Auditors who are responsible for ensuring proper access control and accountability
for their installation are interested in changes to security options, audit records, and
report generation utilities.
For more information, see Chapter 8, “Auditing Considerations” on page 33.
Application Development Considerations
Application development programmers must be aware of new functions introduced
in a new release of RACF. To implement a new function, the application
development personnel should read this book and the following books:
OS/390 Security Server External Security Interface (RACROUTE) Macro
Reference
OS/390 Security Server (RACF) Data Areas
OS/390 Security Server (RACF) Macros and Interfaces
To ensure that existing programs run as before, the application programmers
should be aware of any changes in data areas and processing requirements. This
book provides an overview of the changes that might affect existing application
programs.
For more information, see Chapter 9, “Application Development Considerations” on
page 35.
General User Considerations
RACF general users use a RACF-protected system to:
Log on to the system
Access resources on the system
Protect their own resources and any group resources to which they have
administrative authority
This book provides an overview of the changes that might affect existing
procedures for general users. For more information, see Chapter 10, “General User
Considerations” on page 37.
Chapter 1. Planning for Migration3
Loading...
+ 53 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.