CA 7 Workload Automation

 View Only
  • 1.  administrating from with vs RACF

    Posted Jul 10, 2019 09:49 AM
    Is it possible to allow different USER IDs certian rights from within CA7 or does this happen only through RACF? I thought this was only through RACF but had someone state that they thought it could also be done through CA7. I would like to restrict certain ID's from being able to change the JCL ID only in the DB.1 screen if possible


  • 2.  RE: administrating from with vs RACF
    Best Answer

    Posted Jul 10, 2019 10:05 AM
    YES!!!     Ok, I know it can be done because that is what WE use.  We allow all programmers to VIEW anything in CA7 but they are not allowed to update.  If it is a screen that allows an update then they can't get to that screen to view/or update.   It allows them to do any inquiry and to be able to see the LQ & XQ screens.   "I" don't update it so I'm waiting on my system admin to tell me what/where they do that.   We also have RACF.    As soon as she tells me I will let you know.   

    renate


  • 3.  RE: administrating from with vs RACF

    Broadcom Employee
    Posted Jul 10, 2019 10:42 AM
    Lennie,
     
    This can be controlled by CA 7 internal security or RACF. It all depend on how your CA 7 security is configured. First thing to do is issue CA 7 command: 

    /DISPLAY,ST=SEC   

    This command will display your security options. Over to the right hand side you will see EXTERNAL CONTROL, if COMMAND=ACTIVE that mean RACF is controlling all commands and panels access/authority. Therefore your RACF admin will only grant READ access to resource L2DB1. That mean they can not update "any" field on the DB.1 job definition screen. You can not just prevent them from updating the ONLY the JCL ID field.
     
    -Roderick


  • 4.  RE: administrating from with vs RACF

    Posted Jul 10, 2019 12:32 PM
    Roderick,
         Thanks for the response and command.


  • 5.  RE: administrating from with vs RACF

    Posted Jul 10, 2019 12:32 PM
    Renate,
      Thanks for the reply


  • 6.  RE: administrating from with vs RACF

    Posted Jul 10, 2019 10:57 AM
    This is what the system admin manager said.  (another person does the CA7 system stuff but she is out today)  

    She built the RACF groups for various functions and then you assign the userid the group all via RACF

    Renate