z/OS TSO/E Customization
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Security protected user logs

z/OS TSO/E Customization
SA32-0976-00

If RACF® is installed, your installation is using security labels, and the following operands are modified, the security label of the message is checked to determine if the user is authorized to view the message. Modify the following in the SEND PARMLIB parameter in addition to the operands described in Converting from using the broadcast data set to user logs:
USEBROD
OFF
MSGPROTECT
ON
With these additional values, SEND and LISTBC processing is the same as described in Converting from using the broadcast data set to user logs with the following exceptions:
  • Messages are stored only in the individual user log, not in the broadcast data set.
  • The sender's current security label is stored with the message.
  • To allocate the user log data set, the target user must issue the LISTBC command or logon specifying MAIL.
  • LISTBC allocates both sequential data sets and members of a PDS with the following data set attributes:
    LRECL
    232
    BLKSIZE
    2320
    Primary tracks
    1
    Secondary tracks
    2
  • Before allowing the user to view the message, the user's security label and the message's security label are checked. If the user, attempting to view the message, is not logged on at an appropriate security label, then the user is not allowed to view the message. The message is placed back into the user log and can possibly be viewed when the user is logged on at the proper security label. If the user can never log on at the proper security label (not authorized for the security label of the message), the message is deleted.

For more information about security labels, see .

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014