Setting up PassTickets
For information about PassTickets, see How it works: PassTickets .
Before you begin
To use PassTickets, the systems involved must meet the following requirements:
- The PassTicket generation and validation algorithm means that the system that generates the PassTicket (the originating system) and the system that authenticates it (the destination system) must both use a level of RACF® that supports PassTickets.
- End users must use the same user ID in the destination system as the one that they use in the originating system.
- Because PassTickets are time-stamped, the system clocks for the destination system and the originating system must be synchronized to within the valid time range. While legacy PassTickets are valid for 10 minutes before or after they are generated, enhanced PassTickets are valid only within the configured validity period which can be set between 1 second and 10 minutes. The default value for enhanced PassTickets is 1 minute. For more information about system time differences and synchronization, see Using PassTickets in z/OS Security Server RACF Security Administrator's Guide.