Verify that the z/OSMF server has sufficient authorization

Description

To ensure that the z/OSMF server can be started and stopped by your operations personnel, verify that the z/OSMF started task user ID has sufficient permissions for your environment. By default, this user ID is IZUSVR, but you might have specified another user ID during the configuration process. For example, many installations choose to restrict access to the MVS™ START and STOP operator commands. If so, ensure that the IZUSVR user ID is authorized to the appropriate resource profiles.

By default, both of the z/OSMF started tasks (IZUANG1 and IZUSVR1) run under the started task user ID, IZUSVR.

Table 1 provides more details about this migration action. Use this information to plan your changes to the system.

Table 1. Information about this migration action
Element or feature: z/OSMF
When change was introduced: z/OS V2R1.
Applies to migration from: z/OS V1R13.
Timing: Before installing z/OS V2R2.
Is the migration action required? Yes.
Target system hardware requirements: None.
Target system software requirements: None.
Other system (coexistence or fallback) requirements: None.
Restrictions: None.
System impacts: None.
Related IBM® Health Checker for z/OS® check: None.

Steps to take

To assign a user identity to the started tasks, you can specify a job name (JOBNAME=) on the START command. Here, the job name is used as part of the SAF resource name that is passed to the your security product. If you omit the JOBNAME= specification, the default member names will be used: IZUANG1 and IZUSVR1.

Ensure that the job name is defined in the security profiles for the started tasks. For considerations, see IBM z/OS Management Facility Configuration Guide.

Reference information

For information about starting the started tasks, see IBM z/OS Management Facility Configuration Guide.