Previous Topic: How SAF Resources Are Defined to Use External Security

Next Topic: Remove SAF Authority Using DEFSAF

Permit SAF Authority Using DEFSAF

After you generate the SAF definitions and execute the commands, you can permit additional users to use the predefined SAF resource groups. You permit additional users in a generalized way through the PERMIT action of the DEFSAF utility.

Follow these steps:

  1. Log in to TSO with the user ID that you can use to run the CA OPS/MVS utility program DEFSAF from data set opshlq.CCLXEXEC.
  2. Execute DEFSAF from either the ISPF or TSO command line with ACT(PERMIT) to permit SAF authority.

You have permitted user SOFADMIN to have full access to all SOF commands.

More information:

Implementing External Security with CA Top Secret

Implementing External Security with CA ACF2

Implementing External Security with RACF

Resource Tables and Predefined Resources