Valid on z/OS, z/VSE, and z/VM.
Use the resource keyword to grant administrative authority for a specific resource class to an individual administrator.
This keyword has the following format:
TSS ADMIN(acid) resource(authority-level(s))
The specific resource class RESCLASS from the RDT.
This keyword can be used with:
The CA Top Secret administrator may specify one or more of the following authority levels:
Gives the named "ACID" any of the authorities listed above.
Gives the named "acid" the ability to ADDTO or REMOVE any resource prefixes from the Audit Record. For details, see the Auditor's Guide.
Gives the named "ACID" the ability to employ WHOOWNS and WHOHAS for any resource.
Gives the named "ACID" the administrative authority to ADDTO or REMOVE resources for acids under its scope of control.
Gives the named "ACID" the ability to obtain reports for all resources by employing the utilities TSSUTIL, TSSAUDIT, TSSCPR, and TSSCHART.
Gives the named "ACID" the administrative authority to PERMIT or REVOKE resources for acids under its scope of control.
When granting XAUTH authority to the named “ACID,” the administrator may limit the access levels which the named “ACID” can PERMIT.
If the ADMIN command does not specify an ACCESS clause, the named "ACID" of the command is not allowed to specify an ACCESS keyword in PERMIT commands. As a result, all PERMIT commands issued by the named "ACID" will default to the DEFACC access‑level defined in the RDT
Named "ACID" may permit any resource at any access level.
Named "ACID" may permit any resource at the access level CONTROL.
Named "ACID" may permit any resource at the access level CREATE.
Named "ACID" may permit any resource at the access level DELETE.
Named "ACID" may permit any resource at the access level FEOV.
Named "ACID" may permit any resource at the access level FETCH.
Named "ACID" may permit any resource at the access level NONE.
Named "ACID" may permit any resource at the access level PURGE.
Named "ACID" may permit any resource at the access level READ.
Named "ACID" may permit any resource at the access level REPLACE.
Named "ACID" may permit any resource at the access level SCRATCH.
Named "ACID" may permit any resource at the access level UPDATE.
Named "ACID" may permit any resource at the access level WRITE.
Note: The ACLST of the resource class definition in the RDT governs the appropriate use of ACCESS levels in PERMIT commands for individual resources.
This example allows the RESADM ACID to permit READ access to DATASET resources for ACIDs when both the ACID and the DATASET are owned and within scope.
TSS ADMIN(RESADM) DATASET(XAUTH)
ACCESS(READ)
|
Copyright © 2014 CA Technologies.
All rights reserved.
|
|