Configuring IBM Z NetView authorization of z/OS commands
z/OS system commands issued from the Tivoli Enterprise Portal using Take Action commands, whether issued by a user or triggered by situations or policies, run without any authorization or audit trail. However, you can configure a monitoring server or monitoring agent address space to redirect z/OS® Take Action commands to IBM Z® NetView through the Program to Program Interface (PPI). Take Action commands issued in NetView® make full System Authorization Facility (SAF) calls for authorization. NetView uses the Tivoli Enterprise Portal user ID to determine the NetView operator on which the command authorization is performed. If command authorization passes, the command is executed on the NetView operator. Messages are written to the NetView log to provide an audit trail of the commands and the users that issued them.
About this task
If you enable NetView command authorization on the monitoring server, you must also enable NetView to execute the commands.
Command authorization for the system commands uses the Tivoli Enterprise Portal user ID, which is passed to the NetView program with the command. The user ID passed on a Take Action command determines the user ID that issues the command. The user ID passed when a command is driven from a situation is the user ID that last edited the situation. Only the user ID is used for command authorization. Password validation is not performed.
Take Action forwarding requires NetView V5.3 (or V5.2 with APAR OA18449 applied) or later.