z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Activating global access checking (GLOBAL option)

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

If you have the SPECIAL attribute, you can activate or deactivate global access checking on a class-by-class basis or for all classes. You can specify this option with the GLOBAL and NOGLOBAL operands of the SETROPTS command. The following example shows how to activate global access checking for the FACILITY class.
SETROPTS GLOBAL(FACILITY)
If you specify GLOBAL(*), you activate global access checking for all valid classes. Valid classes you can specify are:
  • The DATASET class
  • The NODE grouping class
  • The SECLABEL grouping class
  • All other classes defined in the class descriptor table, except for the remaining grouping classes

When you use the SETROPTS command to activate (or reactivate) global access checking for a class, RACF® builds (or updates) the in-storage global access checking tables. However, you can use the RDEFINE and RALTER commands to maintain profiles on the database, regardless of whether the global access checking option is active for a class.

NOGLOBAL is in effect when RACF is first initialized.
Note: The SETROPTS GLOBAL(classname) command is propagated when the system is enabled for sysplex communication.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014