z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Profile ownership authority

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

If you own a profile, you can issue the commands and operands shown in Table 1.

Table 1. Commands and operands you can issue if you own a profile
Owner of RACF® profile Commands and operands you can issue if you have this authority
Owner of user profile
ALTUSER1
only with user ID, NAME, OWNER, DFLTGRP, DATA, GRPACC, NOGRPACC, ADSP, NOADSP, REVOKE, NOREVOKE, RESUME, NORESUME, PASSWORD, NOPASSWORD, PHRASE, NOPHRASE, OIDCARD, NOOIDCARD, CLAUTH or NOCLAUTH
DELUSER
with all operands
LISTUSER
with all operands
PASSWORD or PHRASE
only with USER
RACLINK
with all operands
Owner of group profile
ADDGROUP2
with all operands
ADDUSER3
with all operands except OPERATIONS, SPECIAL or AUDITOR
ALTGROUP4
with all operands
ALTUSER
only with GROUP, AUTHORITY or UACC
CONNECT
with all operands except SPECIAL, NOSPECIAL, OPERATIONS or NOOPERATIONS
DELGROUP5
with all operands
LISTGRP
with all operands
REMOVE
with all operands
Owner of resource profile
ALTDSD7
with all operands except NOSET or GLOBALAUDIT
DELDSD7
with all operands except NOSET
LISTDSD7
with all operands
PERMIT
with all operands
RALTER6
with all operands except GLOBALAUDIT
RDELETE
with all operands
RLIST
with all operands
SEARCH
with all operands
1
This command applies to CLAUTH or NOCLAUTH only if you have the CLAUTH attribute for the class to be added or deleted, and the class name is in the class descriptor table (CDT).
2
This command applies to the superior group.
3
This command applies to the default group specified and only if you have the CLAUTH attribute of USER.
4
This command applies to current and new superior groups. You can have JOIN authority in one group and be owner of another group.
5
This command applies to the superior group or group to be deleted.
6
This command applies to the ADDVOL operand only when you also have CLAUTH attribute of TAPEVOL.
7
This command applies to z/OS systems. However, you can issue this command on a z/VM® system to maintain a RACF database that is shared by z/OS and z/VM systems.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014