Changes to RACF classes

This section summarizes the changes that relate to RACF® classes across supported CICS® releases. Use this information to plan the impact of upgrading from one release to another.

If you are upgrading from an end-of-service release, you can find information about the changes that are relevant to those releases in Summary of changes from end-of-service releases.

For other security-related changes, see Changes to security. For changes to transactions, see Changes to CICS transactions.

Table 1. Changes to RACF classes related to command security, by release of CICS TS. These changes are new resource identifiers for SPI commands. See CICS resources subject to command security checking and Resource and command check cross-reference for a list of all of the SPI commands and the RACF ACCESS required for each one.
Change (Command) 5.6 6.1 6.2 CICS TS 6.3
CREATE DUMPCODE NEW: resource identifier DUMPCODE      
INQUIRE JVMENDPOINT NEW: resource identifier JVMENDPOINT      
SET JVMENDPOINT NEW: resource identifier JVMENDPOINT      
INQUIRE NODEJSAPP        
PERFORM JVMSERVER NEW: resource identifier JVMSERVER

ACCESS(UPDATE) is required for the command.

ACCESS(UPDATE) is required for the named JVMSERVER resource identifier.

     
INQUIRE OTEL       NEW: resource identifier OTEL
SET OTEL
Table 2. Changes to RACF classes related to CICS user IDs, by release of CICS TS
Change (User ID) 5.6 6.1 6.2 CICS TS 6.3
Default user ID CHANGED: Default user no longer needs command authority for any CAT 3 CICS transactions. See Default user ID security definitions.      
KERBEROSUSER        
Table 3. Changes to RACF classes related to user profiles, by release of CICS TS
Change 5.6 6.1 6.2 CICS TS 6.3
         
Table 4. Changes to other RACF classes by release of CICS TS
Change (Class) Profile 5.6 6.1 6.2 CICS TS 6.3
FACILITY DFHSIT.HPO        
IDTDATA JWT.applid.userid.SAF NEW: support for JWT with RACF    
SURROGAT userid.DFHEXCI NEW: surrogate user checking for EXCI    
SURROGAT userid.DFHQUERY        
SURROGAT userid.SUBMIT        
SURROGAT userid.DFHTRMID       NEW:

Surrogate security for terminal-based started transactions.