Configuring identity propagation for a remote mode topology (SC04)
This scenario shows how user security information is passed to CICS® Transaction Server and mapped to a user ID in RACF®.
In this scenario, CICS Transaction Gateway and CICS Transaction Server are both on IBM® z/OS®. User security information (the distributed identity) is held in IBM Tivoli® Directory Server and, when it is passed to CICS Transaction Server, the identity is mapped to a user ID in RACF.

Values used in this scenario
Component | Parameter | Where set | Example value |
---|---|---|---|
IBM WebSphere Application Server |
Application security |
IBM WebSphere Admin Console |
Enable application security (check box) |
IBM WebSphere Application Server |
Authentication method |
IBM WebSphere Admin Console |
CTG_idprop (the name of the identity propagation login module) |
CICS TG |
APPLID |
PRODUCT section of ctg.ini |
|
CICS TG |
APPLIDQUALIFIER |
PRODUCT section of ctg.ini |
|
CICS TG |
Server name |
IPICSERVER section of ctg.ini |
CICSA |
CICS TG |
HOSTNAME |
IPICSERVER section of ctg.ini |
|
CICS TG |
PORT |
IPICSERVER section of ctg.ini |
|
CICS TS |
TCPIPService |
TCPIPService definition |
|
CICS TS |
Portnumber |
TCPIPService definition |
|
CICS TS |
APplid |
IPCONN definition on the CICS server |
|
CICS TS |
Networkid |
IPCONN definition on the CICS server |
|
CICS TS |
TCPIPService |
IPCONN definition on the CICS server |
|
CICS TS |
Userauth |
IPCONN definition on the CICS server |
Must be set to |
CICS TS |
IPConn |
IPCONN definition on the CICS server |
|
RACF |
USERID |
RACF resource access list |
|
RACF |
USERDIDFILTER |
RACF resource access list |
|
RACF |
REGISTRY |
RACF |
|
- ctg.ini
- CTGS04A1