| Refer to the following report produced by the z/OS Data Collection: |
Refer to the following report produced by the z/OS Data Collection:
CA 1 external security utilizing ACF2 is accomplished in the manner described in this section.
NOTE: The TMOOPTxx member is specified in the TMOSYSxx member in the data set allocated by the TMSPARM DD statement in the TMSINIT STC. By default, the suffix 00 is used for these members. However, overrides can be specified by PARM value(s) on the EXEC statement in the TMSINIT STC and/or in the TMOSYSxx member.
Review the options and values of the below CA 1 parameters. If the options are set to the specified value, this is not a finding.
CA 1 SECURITY OPTIONS - ACF2
BATCH YES obsolete as of r12.0
CATSEC NO obsolete as of r12.0
CREATE see Note 1
FUNC YES see Note 2
OCEOV NO see Note 3
PMASK Do not specify or change
UX0AUPD NO see Note 4
Note 1 The CREATE parameter defines the level of access that is required to create a data set on tape. The default value is UPDATE. However, the vendor recommends the value be set to CREATE if you are running CA Top Secret or ACF2 and ALTER if you are running RACF.
Note 2 The FUNC option provides supplementary security for BLP access. The tape label bypass privilege must still be specified in the ACF2 user LID record to allow access to BLP processing.
Note 3 The CA 1 security option, OCEOV, is set to NO because ACF2 obtains control of data set OPEN/CLOSE processing before the CA 1 intercept. The vendor recommends that the first security call be used and that this CA 1 control option be turned OFF. Therefore, TAPEDSN must be specified in the OPTS option in the ACF2 GSO record.
Note 4 The UX0AUPD will specify YES only if you alter the fields in the TMC and the TMSUXxA (for r11.5 and below) or TMSXITA (for r12.0 and above) is changed.