z/OS Cryptographic Services PKI Services Guide and Reference
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Deciding the value of restrict_surrog

z/OS Cryptographic Services PKI Services Guide and Reference
SA23-2286-00

Use the following decision table to determine the value of restrict_surrog in Table 1. The restrict_surrog variable determines if the RESTRICTED attribute is assigned to the surrogate user ID. The RESTRICTED attribute limits the resources available to this user ID.

By default, IKYSETUP does not assign the RESTRICTED attribute to the surrogate user ID. Guideline: Do not change the default the first time you run IKYSETUP but change it before going into a production environment. For more information, see the topic about defining groups and users in z/OS Security Server RACF Security Administrator's Guide.

Table 1. Decision table for restrict_surrog
If … Then …
You want to assign the RESTRICTED attribute to the surrogate user ID … Set restrict_surrog=1
You do not want to assign the RESTRICTED attribute to the surrogate user ID … Do not change the default restrict_surrog=0

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014