z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Protecting terminals

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

There are several methods of controlling the use of terminals that are connected to your system. The following sections describe these methods:
  • Creating profiles in the TERMINAL and GTERMINL classes. You must give users at least READ access authority in order to allow them to use protected terminals. You must do this before using any of the other methods for controlling terminals.
  • Controlling the use of undefined terminals. By specifying TERMINAL(NONE) on the SETROPTS command, you can prevent users from logging on to terminals unless the terminals are protected by profiles in the TERMINAL or GTERMINL classes.
    Important: Do not protect undefined terminals unless you have created profiles that allow users to access the terminals they currently use.
  • Limiting specific groups of users to specific terminals. By specifying NOTERMUACC on the ADDGROUP or ALTGROUP command, you can restrict users in those groups to terminals whose access lists specifically allow the user or the user's group to use the terminal.
  • Limiting the times that a terminal can be used. By specifying the WHEN operand on the RDEFINE and RALTER commands for profiles in the TERMINAL and GTERMINL classes, you can specify the days and times that users can log on to terminals.
  • Using security labels to control terminals. If the SECLABEL class is active, you can control access to terminals by specifying security labels for profiles in the TERMINAL and GTERMINL classes.
  • Using the TSO LOGON command with the RECONNECT operand. TSO allows verification and checking so that a user can resume an interrupted session from a new terminal.

For a description of authorization checking for terminals, see Authorizing access to RACF-protected terminals.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014