Configuring the TS7700 for RACF
Configuration of the TS7700 to use the Resource Access Control Facility (RACF) should be performed through the management interface by a customer system administrator.
About this task
Procedure
- Log in to the management interface for the TS7700 Cluster attached to the IBM Z® host where RACF for LDAP has already been configured.
- Go to Access > Security Settings > Add External policy
- On the Authentication Policies table, select Add Direct LDAP policy from the Select Action menu.
- In the Server Settings section, create a policy name that can be identified as using RACF.
- Select Allow an IBM service representative to connect through physical access if available.
- The Primary Server URL must be the same as the LDAP server.
- The Base Distinguished Name must
match the
SDBM_SUFFIX
value. - In the LDAP Attributes section, enter values for all LDAP attributes and filters.
- In the Server Authentication section,
specify a User Distinguished Name using all
parameters specific to RACF and defined in the LDAP Attributes section.
For example, if Username Attribute=racfid, Group
Member Attribute=user, and Group Name Attribute=RACF,
then this field would have a value like:
racfid=RACFUSER,profiletype=user,cn=RACF
. - Enter a password.
- Click OK.