Define editor profiles to control access to the editors
To control authorization for the Situation Editor, Object Editor, and ISPF Editor in the OMEGAMON® enhanced 3270 user interface, the security administrator must define SAF resource profiles, as described in this topic.
Before you begin
- Situation Editor
- In this editor, you can browse defined situations. If you are authorized to make updates in the editor, you can also create, edit, start, and stop situations.
- Object Editor
- In this editor, you can browse object groups in the hub monitoring server. If you are authorized to make updates in the editor, you can also create or edit the object groups.
- ISPF Editor
- In this editor, you can browse members in data sets that are allocated to the enhanced 3270 user interface address space. If you are authorized to make updates in the editor, you can also modify the members.
- Option 1: Authorize the users who can either invoke and make updates in the editors, or cannot access the editors. (With this option, a user cannot be authorized to browse only.)
- Option 2: Authorize the users who can invoke and make updates in the editors, can invoke and browse in the editors, or cannot access the editors.
Before you begin, decide which configuration option to implement at your site.
- Related links
- Editor security scenarios and examples
About this task
KOBUI.ADMIN.editor
KOBUI.ADMIN.editor.UPDATE
where:
- KOBUI
- Is a literal qualifier value. KOBUI is a qualifier for the enhanced 3270 user interface.
- ADMIN
- Is a literal qualifier value. ADMIN is a qualifier for enhanced 3270 user interface functions. For information about other features protected by SAF profiles using this qualifier, see Define profiles for additional interface activities.
- editor
- Identifies the editor. Use SITEDITOR for the Situation Editor, OBJECTEDITOR for the Object Editor, and ISPFEDIT for the ISPF Editor.
- UPDATE
- Is a literal. This suffix is used only when configuring different profiles for controlling update and browse authorizations separately.
To be authorized for an editor resource, a user or group must be permitted READ (or UPDATE) access to the associated resource profile; for editor profiles, both READ and UPDATE access provide the same capability.
KOBUI.ADMIN.** defined at your site, be aware that it might impact expected editor authorizations. See Authorizing access with generic profile definition.O4SRV.**
where O4SRV is a qualifier for monitoring server tables.These profiles are defined to the SAF general resource class identified by the RTE_SECURITY_CLASS parameter. For more information about the defining the class, see Define a SAF general resource class for securing access to OMEGAMON resources.
- Option 1: Authorize the users who can either invoke and make updates in the editors, or cannot access the editors. (With this option, a user cannot be authorized to browse only.)
- Option 2: Authorize the users who can invoke and make updates in the editors, can invoke and browse in the editors, or cannot access the editors.
Procedure
You can implement either of the following options for controlling access to the Situation Editor, Object Editor, and ISPF Editor: