

Resources › CASECAUT Resource Class—Authorize Restricted Administrative Priviliges
CASECAUT Resource Class—Authorize Restricted Administrative Priviliges
Valid on z/OS.
Use CASECAUT to authorize users with no administrative authorities to change certain password related fields for other users within their scope and issue digital certificate and keyring related commands.
When used with TSS ADDTO/REMOVE, this resource class has the following format:
TSS ADDTO(acid) CASECAUT(prefix,prefix...)
- Prefix length
-
Two to twenty-six characters
- Capacity of list
-
One to eight prefixes per TSS command
When used with TSS PERMIT/REVOKE, this resource class has the following format:
TSS PERMIT(acid) CASECAUT(prefix(es))
- Prefix length
-
Two to forty-four characters
- Capacity of list
-
One to eight prefixes per TSS command
This keyword uses:
- The commands ADDTO, REMOVE, PERMIT, REVOKE, WHOHAS, and WHOOWNS
- The ACID types User, Profile, Department, DivisionZone, DCA, VCA, ZCA, LSCA, SCA, and MSCA when used with TSS ADD/REMOVE
- The ACID types User, Profile, Department, Division, Zone, DCA, VCA, ZCA, LSCA, SCA, and MSCA when used with TSS PERMIT/REVOKE
- CASECAUT(OWN) authority to ADD or REMOVE ownership of CASECAUT resources
- CASECAUT(XAUTH) authority to PERMIT or REVOKE access to CASECAUT resources
The administrator can:
- Specify the access levels: NONE, USE, UPDATE, PRIVILEG, CONTROL, and GRANT. If ACCESS is not specified, CA Top Secret defaults to USE access
- Use any of the following methods to control access to CASECAUT: Expiration, Facility, Time/Day, and Actions.
Masking
The CASECAUT resource class supports all masking characters.
Examples: CASECAUT resource class
- This example adds ownership of prefix TSSCMD to SYSDEPT acid:
TSS ADDTO(SYSDEPT) CASECAUT(TSSCMD)
- This example removes ownership:
TSS REMOVE(SYSDEPT) CASECAUT(TSSCMD)
- This example permits USER01 to change the password field for other users within scope:
TSS PERMIT(USER01) CASECAUT(TSSCMD.USER.REPLACE.PASSWORD)
- This example revokes access:
TSS REVOKE(USER01) CASECAUT(TSSCMD.USER.REPLACE.PASSWORD)
Copyright © 2014 CA Technologies.
All rights reserved.
 
|
|