z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Authorizing the use of your installation's printers

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

You can use RACF® to control who can use your installation's printers. Printers at your installation are defined to JES3 by DEVICE statements in the JES3 initialization stream. Printers are also defined in the Hardware Configuration Definition (HCD) program.

To authorize or restrict the use of your installation's printers, perform the following steps:
  1. Ask your JES system programmer for the following information:
    • A 4-part profile name that represents the printer. The format of the 4-part profile name is:
      sysname.dev-class.modelno.ddd
      where:
      sysname
      identifies the name of the system.
      dev-class
      specifies the type of device. For printers, you must always specify unit record (UR).
      modelno
      specifies the model number of the printer.
      ddd
      specifies the device number associated with the printer.
    • The universal access authority associated with the printer. A UACC of READ indicates the printer can be allocated to all users in your installation. A UACC of NONE indicates the printer can only be allocated to the users you specify.
    • A list of users and groups that have access other than the UACC. READ access allows the device to be allocated to the job submitted by the specified user.
    • The security label associated with the printer (if security labels are being used).
  2. Create a profile in the DEVICES class to protect each writer:
    RDEFINE DEVICES profile-name UACC(NONE)
  3. When you are ready to start using the protection provided by the profiles you have created, activate the DEVICES classes:
    SETROPTS CLASSACT(DEVICES)

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014