Previous Topic: Tape Encryption Processing with CA ACF2

Next Topic: Control the SAF Interface (BES.SECURITY)

Activate and Control the CA Tape Encryption SAF Interface for CA ACF2

The CA Tape Encryption SAF Interface is controlled at the global level for all BESn subsystems. The CA@BES resource profile definition, BES.SECURITY, requires a valid $USERDATA security control parameter. The $USERDATA security control parameter is used to determine whether the SAF Interface is enabled to protect CA Tape Encryption resources (for example; commands, keys, and utilities) and perform data set selection using CA ACF2 data set selection profiles. The security control parameter can be added or modified dynamically but you must issue the appropriate CA ACF2 refresh commands to rebuild the CA@BES storage profiles. In addition to the CA ACF2 refresh commands, the CA Tape Encryption reload command needs to be issued for all subsystems currently executing to reload the BES control tables.