OMEGAMON enhanced 3270 user interface security
The OMEGAMON® enhanced 3270 user interface uses the system authorization facility (SAF) interface to authorize and authenticate users. Planning for security includes deciding who requires access to the OMEGAMON enhanced 3270 user interface, what information they may view, and what Take Action commands they should have permission to invoke; choosing or creating an SAF class that will contain the SAF resources; then ensuring that the required IDs are given the appropriate authority to those resources.
The existence of the SAF user ID and its validity are always checked. The enhanced 3270 user interface also runs SAF authorization checks to determine if the user has the authority to perform the following actions:
- Log on to this instance of the enhanced 3270 user interface
- End-user activities
- View data for a specific attribute group (table) on a specific managed system
- Transmit a Take Action request to a specific managed system
- Change auto-update preferences
- Enter a command on the command line
- Create and modify a profile member name with the same name as the user ID of the user
- Use a specific hub monitoring server from within the enhanced 3270 user interface
- Use the Situation Editor, Object Editor, and ISPF Editor functions
- Administrative activities
- List enhanced 3270 user interface users, and optionally end a user's session
- Start or stop user interface tracing
- Start or stop internal tracing
- Modify (Save As) any PDS member that is named with a different user ID to that of the current user
- Configure near-term history
- Stop a user session
- Send commands and queries to a given hub monitoring server via the enhanced 3270 user interface for IBM Tivoli Management (ITM) CMS (TEMS), Service Index or SOAP consoles.
- Retrieve user session initialization hub monitoring server information
- Configure multi-tenancy
- If no SAF security class is supplied (value for RTE_SECURITY_CLASS is missing or blank), users may log on to the OMEGAMON enhanced 3270 user interface, may access data through queries, but may not issue Take Action commands.
- If a SAF security class is supplied, but the class is not defined and active in SAF, no one may log on to the OMEGAMON enhanced 3270 user interface.
- If a SAF security class is supplied, and is defined and active in SAF, but no logon profile is defined, no one may log on to the OMEGAMON enhanced 3270 user interface.
- If a user is able to log on, and a different security class than the one used for logon is used for queries or for Take Action commands (but is not activated or resources are not defined in that security class), everyone can view data for any managed system and perform other commands and activities, but all Take Action commands are denied.
- If a security class name is configured, resource profiles must be defined to control log on, data access, and Take Actions, and users must be given access to those profiles.
- Define an SAF general resource class.
- Define logon profiles to control access to the enhanced 3270 user interface.
- Define Take Action profiles to control access to enhanced 3270 user interface data actions.
- Define Query profiles to control access to OMEGAMON enhanced 3270 user interface data sources.
- Define profiles to control permissions to additional activities performed using the enhanced 3270 user interface.
- Permit access to the profiles by appropriate personnel.
At a minimum, update the security settings to secure the Take Action function. Failure to correctly secure this powerful function of the OMEGAMON enhanced 3270 user interface might give all users full control to modify the managed system, including starting and stopping applications.
- Display a member list for a data set
- Browse the contents of a data set member
- Save a data set member