Use the command control commands to define each console command you want to protect. Use this control statement as input to TBESAF99 to generate control statements for your security system.
You have the option to control each eligible CA Tape Encryption console command at the global level for all BES subsystems or at the local level for each BES subsystem. The following guidelines apply to this command:
This command has the following format:
BESn TYPE=COMMAND,
NAME=command_name.qualified_name
Indicates the BES subsystem. To specify a global command protection profile for a specified console command for all BES systems, start the command with BES and do not specify a BES subsystem.
Note: For CA ACF2, you must specify the BES subsystem number.
Indicates that this control statement defines a protection profile for a console command.
Specifies the name of the CA Tape Encryption console command and its qualified name, if any. Only the commands listed here are eligible to be controlled by this feature. Some of these commands have qualifying command parameters and some do not. If a command that has qualifying command parameters is on this list and a qualifying parameter is not listed, all forms of the command are governed by the command protection profile, unless otherwise noted. If a command with a qualifying command parameter is on this list, only that form of the command is governed by the command protection profile. Options for this parameter are as follows:
Specifies the COMPROMISE= command.
Specifies all forms of the DISPLAY command.
Specifies the DUMP command.
Specifies all forms of the MIGRATE= command.
Specifies the RELOAD=PASSPHRASE command.
Specifies the REFRESH=CAEKM_API_OPTIONS command.
Specifies the REFRESH=CODEBOOKS command.
Specifies the REFRESH=KEYRINGS command.
Specifies the REFRESH=NKMPARMS command.
Specifies the REFRESH=OPTIONS command.
Specifies the REFRESH=SYMKEYS command.
Specifies all forms of the RELOAD= command, except for the RELOAD=PASSPHRASE command.
Specifies the SET CONSOLE command.
Specifies the SHUTDOWN command.
Specifies the START NKM command
Specifies the STOP NKM command.
Example: Global command definition for REFRESH=SYMKEYS command
This example defines to all BES subsystems the REFRESH=SYMKEYS command.
BES TYPE=COMMAND,NAME=REFRESH.SYMKEYS
Example: Local command definition for DISPLAY commands
This example defines to BES1 all commands that begin with DISPLAY. This includes any form of the DISPLAY command, for example, DISPLAY ACTIVE, DISPLAY BUFFER, DISPLAY SECURITY, and so on.
BES1 TYPE=COMMAND,NAME=DISPLAY
Example: Local command definition for RELOAD=PASSPHRASE command
This example defines to BES2 the RELOAD=PASSPHRASE command.
BES2 TYPE=COMMAND,NAME=PASSPHRASE
| Copyright © 2011 CA. All rights reserved. | Tell Technical Publications how we can improve this information |