Changes to RACF classes
This section summarizes the changes that relate to RACF® classes across supported CICS® releases. Use this information to plan the impact of upgrading from one release to another.
If you are upgrading from an end-of-service release, you can find information about the changes that are relevant to those releases in Summary of changes from end-of-service releases.
For other security-related changes, see Changes to security. For changes to transactions, see Changes to CICS transactions.
RACF classes related to command security
These changes are new resource identifiers for SPI commands. See CICS resources subject to command security checking and Resource and command check cross-reference for a list of all of the SPI commands and the RACF ACCESS required for each one.
- 6.3 CICS TS 6.3
-
- NEW:
-
- Command INQUIRE OTEL has new resource identifier OTEL.
- Command SET OTEL has new resource identifier OTEL.
- 5.6 CICS TS 5.6
-
- NEW:
-
- Command CREATE DUMPCODE has new resource identifier DUMPCODE.
- Command INQUIRE JVMENDPOINT has new resource identifier JVMENDPOINT.
- Command SET JVMENDPOINT has new resource identifier JVMENDPOINT.
- Command PERFORM JVMSERVER has new resource identifier JVMSERVER. ACCESS(UPDATE) is required for the command. ACCESS(UPDATE) is required for the named JVMSERVER resource identifier.
RACF classes related to CICS user IDs
- 5.6 CICS TS 5.6
-
- CHANGED:
-
- Default user no longer needs command authority for any CAT 3 CICS transactions. See Default user ID security definitions.
RACF classes related to user profiles
There are no changes for RACF classes related to user profiles.
Other RACF classes
- 6.3 CICS TS 6.3
-
- NEW:
-
- Class SURROGAT, profile userid.DFHTRMID, has Surrogate security for terminal-based started transactions.
- 5.6 CICS TS 5.6
-
- NEW:
-
- Class IDTDATA, profile JWT.applid.userid.SAF, has support for JWT with RACF.
- Class SURROGAT, profile userid.DFHEXCI, has surrogate user checking for EXCI.