You want to grant the user, MSMUSR3, access to the following actions only:
Issue the following CA ACF2 for z/OS commands:
SET R(MSM) COMPILE STORE $KEY(LOGON) TYPE(MSM) UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM) COMPILE STORE $KEY(ADMIN) TYPE(MSM) SETTINGS.USER.- UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM) COMPILE STORE $KEY(SC) TYPE(MSM) @ACTION.INSTPKG.- UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM) COMPILE STORE $KEY(SMPE) TYPE(MSM) @ACTION.MIGRATE.- UID(*****MSMUSR3) SERVICE(READ) ALLOW @ACTION.REMOVECSI.- UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM)
COMPILE STORE
$KEY(SYSREG) TYPE(MSM)
UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM) COMPILE STORE $KEY(METHOD) TYPE(MSM) @DISPLAY.- UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM) COMPILE STORE $KEY(DEPLOY) TYPE(MSM) @SELF.- UID(*****MSMUSR3) SERVICE(READ) ALLOW
SET R(MSM) COMPILE STORE $KEY(CONFIG) TYPE(MSM) @ACTION.IMPL UID(*****MSMUSR3) SERVICE(READ) ALLOW
| Copyright © 2013 CA. All rights reserved. |
|