Previous Topic: Auditing MLSNext Topic: Configuring a Multilevel Secure System


Tracing SAF Requests

The SECTRACE command lets you trace any security request made to the System Authorization Facility (SAF). SAF is a z/OS component that permits resource managers of the operating system to request security services. SAF's primary function is to route security information between the application and the security product that resides with the z/OS software. Any program using SAF automatically interfaces with CA Top Secret because CA Top Secret translates SAF security requests into CA Top Secret requests.

Tracing UNIX System Services (OMVS)

The SECTRACE facility can be used to trace SAF requests made by OMVS.

When MLS is active on a system, the following MLS-related data appears in the OMVS SECTRACE output:

FSP SECLABEL=security label

The 8-byte file or directory security label or, *NONE*, if no security label exists

USER SECLABEL=security label

The 8-byte session security label or, *NONE*, if no security label exists