Previous Topic: What Does CA ACF2 for z/VM Control?Next Topic: What is the System Request Facility?


Components of CA ACF2 for z/VM

CA ACF2 for z/VM consists of the following components:

CA ACF2 for z/VM Service Machine

This service machine contains the internal control tables that CA ACF2 for z/VM uses to validate logon requests and requests for access to minidisks, CMS file IDs, MVS data sets, and ATTACH commands. It processes all requests to update the databases and generates logging records.

CA ACF2 for z/VM Modules in CP

CA ACF2 for z/VM modules are inserted into CP to control CP‑related functions. These functions include validation calls, system status changes, communication with the service machine, and command limiting rule interpretation and compilation.

CA ACF2 for z/VM Modules in CMS

CA ACF2 for z/VM intercept code is inserted into CMS and becomes part of the CMS system. These modules provide functions such as communication with the CA ACF2 for z/VM service machine and CMS file‑level security.

CA ACF2 for z/VM Database Recovery

The CA ACF2 for z/VM ACFRECVR utility recreates one or all of the databases if they become damaged. ACFRECVR accepts one or more of the database backup files and selected database maintenance logging records and merges them to create a current database.

CA Earlâ„¢

The CA Earl™ facility is provided with CA ACF2 for z/VM. It’s is a powerful, easy‑to‑use reporting language with 24 straightforward commands. With CA Earl™, you can:

CA ACF2 for z/VM Full-screen Feature

This is a menu‑driven, easy‑to‑use method of maintaining logonids, writing access rules and resource rules, and running CA ACF2 for z/VM reports. To access the full‑screen primary menu, enter the following command from CMS:

ACFFS

CA ACF2 for z/VM Security and Maintenance Reports

We provide a report utility (ACFRPTS) to format CA ACF2 for z/VM reports. Four basic types of reports are available:

Data and Resource Logging Violation Reports

These reports contain logging and violation records for the five reports below.

ACFRPTCL

Reports each command limiting and diagnose limiting logging or violation record.

ACFRPTCT

Reports each ACFSERVE command issued, the type of command, and the user issuing the command.

ACFRPTDL

Reports the violation and logging records for all commands issued to the DirMaint service machine.

ACFRPTDS

Reports the logging and violation records for minidisks, CMS files, OS data sets, DOS files, and attachable DASD devices.

ACFRPTRV

Reports the resource violation and logging records for all activity related to user‑defined logical resources.

Database Maintenance Reports

These reports document updates to the CA ACF2 for z/VM databases.

ACFRPTEL

Reports modifications made to resource rule sets and other Infostorage database records.

ACFRPTLL

Reports modifications to the Logonid database.

ACFRPTRL

Reports modifications to the Rule database.

Cross Reference Reports

ACFRPTPW

Journals each unsuccessful system access attempt.

See the Reports and Utilities Guide for complete information on these and all reports.

CA ACF2 for z/VM Commands

CA ACF2 for z/VM provides a powerful set of tools to maintain the following:

CA ACF2 for z/VM also provides commands to compile, store and decompile the following:

ACF

Primary interface with the ACF2 service machine for creating, deleting, and maintaining CA ACF2 for z/VM records.

ACFCOMP

Compiles an access rule set with one command. You can enter input for the rule set directly from the terminal or from a CMS file.

ACFDCMP

Decompiles an access rule set at the terminal. Alternately, you can write the decompiled rule set to a CMS file for easy modification.

ACFNRULE

Inserts or deletes a single rule entry in an access rule set. It provides a convenient way to quickly edit a rule set.

ACFSERVE

A CP command that lets you communicate directly with the ACF2 service machine. The ACFSERVE commands can instruct CA ACF2 for z/VM to take a database backup, reset a password violation count, manage the SMF records created by CA ACF2 for z/VM, reload resident rules, display the status of CA ACF2 for z/VM, or switch SMF files.

CA ACF2 for z/VM Utilities

We provide many utilities to assist in the initial implementation and installation of CA ACF2 for z/VM. We also provide utilities to help streamline ongoing maintenance activities, recover databases, and SMF management.

CA ACF2 for z/VM Help Files

A set of online help files can assist you when using the ACF command, full‑screen, and other CA ACF2 for z/VM‑supplied commands.

Message Help

Help is also available for all CA ACF2 for z/VM messages. If you need help with a message, enter the following command:

HELP message_number

A help screen displays with information on that message.