Customization of zSecure configuration data sets
After you have created the zSecure configuration data sets, you can customize the members and create copies to be used for different user communities or different z/OS® images. For example, to configure zSecure to be used by different groups of users such as RACF® administrators and RACF auditors on the same image, create copies of member C2R$PARM. Then, configure each member separately. When copying and configuring the members, the following rules and guidelines apply:
- Do not use member names that begin with C2R or CKR.
- For zSecure
Admin users,
all configuration members within the same data set share the C2RSMUMA,
C2RSMUMH, and C2RSMUMP members that specify zSecure
Admin settings
used to create new RACF
userids. See Configuring zSecure Admin to create new userids in the RACF database. To specify different values for these members:- Copy the entire CKRPARM data set to the system from which you want to run zSecure Admin.
- Update the CKRPARM members as required.
- You can create multiple copies of CKRPROF to customize the ISPF interface for different z/OS images or different user communities.
- The CKRJOBS data set is intended to be further customized. For example, you might specify different configuration members depending on the environment where each job is to run. For this reason, consider creating multiple copies of the CKRJOBS data set.
- For zSecure Audit users that use option AU.R - Rule-based compliance evaluation: Remove the comment from the SET CKACUST parameter and update the data set name.