Previous Topic: TELNETNext Topic: WebSphere


Securing TELNET for USS

When using TELNET under OMVS, RLOGIN runs under its own ACID until the user successfully signs on. The ID of this ACID is specified in the configuration file etc/inetd/conf. TELNET is delivered specifying an ID of OMVSKERN and must be defined with both superuser and daemon authority.

Example: defining an ACID with dual authority

In this example an ACID is defined with both superuser and daemon authority:

TSS CRE(OMVSKERN) TYPE(USER)
                  NAME('OMVS ACID')
                  PASS(password,0)
                  DEPT(dept)
TSS ADD(OMVSKERN) UID(0)
                  GROUP(OMVSGRP)
                  DFLTGRP(OMVSGRP)
                  HOME(/)
                  OMVSPGM(/bin/sh)

If you are using OMVSKERN, it is likely that this ID was defined as part of your OMVS installation.

If you are securing daemon authority, the TELNET server ID must have the permission:

TSS PER(OMVSKERN) IBMFAC(BPX.DAEMON)