Portal | Manuals | References | Downloads | Info | Programs | JCLs | Mainframe wiki | Quick Ref
IBM Mainframe Forum Index
 
Register
 
IBM Mainframe Forum Index Mainframe: Search IBM Mainframe Forum: FAQ Memberlist Profile Log in to check your private messages Log in
 
Don't allow CICS to submit batch jobs

 
Post new topic   Reply to topic    IBMMAINFRAMES.com Support Forums -> JCL & VSAM
View previous topic :: :: View next topic  
Author Message
prino

Senior Member


Joined: 07 Feb 2009
Posts: 1161
Location: Vilnius, Lithuania

PostPosted: Mon Jul 25, 2016 3:26 pm    Post subject: Don't allow CICS to submit batch jobs
Reply with quote

The title tells it all, we ("that system") want to totally prevent users from submitting batch jobs from CICS using RACF.

Any clues? Feel free to PM me if replies are sensitive.
Back to top
View user's profile Send private message

expat

Global Moderator


Joined: 14 Mar 2007
Posts: 8784
Location: Welsh Wales

PostPosted: Mon Jul 25, 2016 5:32 pm    Post subject:
Reply with quote

If CICS uses the INTRDR, then that can be controlled via RACF
Back to top
View user's profile Send private message
steve-myers

Active Member


Joined: 30 Nov 2013
Posts: 753
Location: The Universe

PostPosted: Mon Jul 25, 2016 7:42 pm    Post subject:
Reply with quote

expat wrote:
If CICS uses the INTRDR, then that can be controlled via RACF

There is a RACF class PROPCNTL, resource xxxx, where xxxx is the jobname of the CICS, but it appears the "perp" was bypassing whatever CICS interface is used for batch job submission, which presumably tests this resource.

Outside of TSO, there is no RACF capability to deny use of INTRDR.
Back to top
View user's profile Send private message
expat

Global Moderator


Joined: 14 Mar 2007
Posts: 8784
Location: Welsh Wales

PostPosted: Mon Jul 25, 2016 7:54 pm    Post subject:
Reply with quote

steve-myers wrote:
Outside of TSO, there is no RACF capability to deny use of INTRDR.


https://www.ibm.com/support/knowledgecenter/SSLTBW_2.2.0/com.ibm.zos.v2r2.hasa300/has2v5_Securing_resources.htm
Back to top
View user's profile Send private message
steve-myers

Active Member


Joined: 30 Nov 2013
Posts: 753
Location: The Universe

PostPosted: Mon Jul 25, 2016 8:28 pm    Post subject:
Reply with quote

Interesting. I didn't know about JESINPUT/INTRDR. It will need more analysis.
Back to top
View user's profile Send private message
Rohit Umarjikar

Senior Member


Joined: 21 Sep 2010
Posts: 2267
Location: NY,USA

PostPosted: Mon Jul 25, 2016 9:42 pm    Post subject:
Reply with quote

Also,
Code:
Attention:
Any CICS user, whether signed on or not, is able to submit jobs that use the SURROGAT userid, if the CICS userid has authority for SURROGAT. If your installation is using transient data queues to submit jobs, you can control who is allowed to write to the transient data queue that goes to the internal reader. However, if your installation is using EXEC CICS SPOOLOPEN to submit jobs, you cannot control who can submit jobs (without writing an API global user exit program to screen the commands). CICS spool commands do no CICS resource or command checking.
You can use an EXEC CICS ASSIGN USERID command to find the userid of the user who triggered the application code. Application programmers can then provide code that edits a USER operand onto the JOB card destined for the internal reader.For a complete description of surrogate job submission support, see the z/OS Security Server RACF Security Administrator's Guide

SETROPTS
LOGON/JOB INITIATION - NOT AUTHORIZED TO APPLICATION
Back to top
View user's profile Send private message
View previous topic :: :: View next topic  
Post new topic   Reply to topic    IBMMAINFRAMES.com Support Forums -> JCL & VSAM All times are GMT + 6 Hours
Page 1 of 1

 

Search our Forum:

Similar Topics
Topic Author Forum Replies Posted
This topic is locked: you cannot edit posts or make replies. ASSIST/GT with CICS BPranav CICS 1 Mon Sep 16, 2019 9:26 pm
This topic is locked: you cannot edit posts or make replies. COBOL/CICS with real time MQ Series u... BPranav CICS 2 Mon Sep 16, 2019 9:19 pm
No new posts Can rexx be exected in cics(online) e... RAVISANKAR07 All Other Mainframe Topics 3 Wed Sep 04, 2019 5:51 pm
No new posts REXX - CLIST program to be invoked af... pkmurali CLIST & REXX 5 Wed Sep 04, 2019 4:31 pm
No new posts Trying to document a weird condition ... John Poulakos CICS 0 Fri Aug 30, 2019 11:19 pm

Facebook
Back to Top
 
Job Vacancies | Forum Rules | Bookmarks | Subscriptions | FAQ | Polls | Contact Us