A.1 z/OS RACF Schema

The following tables describe the schema used by the driver.

Table A-1 Class User Attribute Descriptions

Attribute Name

Description

DirXML-RACF-adsp

Automatic Data Set Protection (ADSP) attribute for the user.

DirXML-RACF-auditor

AUDITOR attribute for the user.

DirXML-RACF-category

Installation-defined security categories.

DirXML-RACF-cics-opclass

CICS operator class numbers for basic mapping support (BMS) messages,

DirXML-RACF-cics-opident

CICS operator identification for BMS.

DirXML-RACF-cics-opprty

CICS operator priority.

DirXML-RACF-cics-timeout

CICS operator idle timeout value in hours and minutes.

DirXML-RACF-cics-xrfsoff

CICS user signoff for XRF takeover.

DirXML-RACF-clauth

Classes for which user is allowed to define profiles.

DirXML-RACF-data

Installation-defined data for the user.

DirXML-RACF-dce-autologin

Whether z/OS UNIX DCE is to automatically log this user in.

DirXML-RACF-dce-dcename

DCE principal name for the user.

DirXML-RACF-dce-homecell

DCE cell name for the user.

DirXML-RACF-dce-homeuuid

DCE universal unique identifier (UUID) for the cell user is defined to.

DirXML-RACF-dce-uuid

DCE universal unique identifier (UUID) of the DCE principal defined in DCENAME.

DirXML-RACF-dfltgrp

Default group for the user.

DirXML-RACF-dfp-dataappl

DFP data application for the user.

DirXML-RACF-dfp-dataclas

Default data class for the user.

DirXML-RACF-dfp-mgmtclas

Default management class for the user.

DirXML-RACF-dfp-storclas

Default storage class for the user.

DirXML-RACF-eim-ldapprof

Name of profile in the LDAPBIND class for the user.

DirXML-RACF-groups

Group connection information for the user.

DirXML-RACF-grpacc

Specifies whether group data sets protected by DATASET profiles defined by the user are automatically accessible to other users in the group.

DirXML-RACF-kerb-encrypt-des

Whether DES encrypted keys are allowed for use.

DirXML-RACF-kerb-encrypt-des3

Whether DES3 encrypted keys are allowed for use.

DirXML-RACF-kerb-encrypt-desd

Whether DESD encrypted keys are allowed for use.

DirXML-RACF-kerb-kerbname

User’s local kerberos-principal-name.

DirXML-RACF-kerb-maxtktlfe

The max-ticket-life in seconds.

DirXML-RACF-language-primary

User’s primary language.

DirXML-RACF-language-secondary

User’s secondary language.

DirXML-RACF-lnotes-sname

Lotus Notes* short-name.

DirXML-RACF-model

User’s model data set profile.

DirXML-RACF-name

User name.

DirXML-RACF-nds-uname

Novell Directory Services® for OS/400 user-name.

DirXML-RACF-netview-consname

Default MCS console name identifier.

DirXML-RACF-netview-ctl

Whether a security check is performed for this NetView operator for span or cross-domain logon.

DirXML-RACF-netview-domains

NetView program identifiers in another NetView domain where this operator can start a cross-domain session.

DirXML-RACF-netview-ic

NetView initial command list string.

DirXML-RACF-netview-msgrecvr

Whether this operator receives unsolicited messages not routed to a specific NetView operator.

DirXML-RACF-netview-ngmfadmn

Whether NetView operator has administrator authority to NetView Graphic Monitor Facility (NGMF).

DirXML-RACF-netview-ngmfvspn

Reserved for future use by the NetView Graphic Monitor Facility.

DirXML-RACF-netview-opclass

NetView scope classes for which the operator has authority.

DirXML-RACF-omvs-assizemax

The RLIMIT_AS hard limit resource value the user’s processes receive when they are dubbed a process.

DirXML-RACF-omvs-cputimemax

The RLIMIT_CPU hard limit resource value the user’s processes receive when they are dubbed a process.

DirXML-RACF-omvs-fileprocmax

The maximum number of files the user is allowed to have concurrently active or open.

DirXML-RACF-omvs-home

The user’s hierarchical file system (HFS) home directory pathname.

DirXML-RACF-omvs-mmapareamax

The maximum amount of data space storage, in pages, that can be allocated by the user for HFS file memory mapping.

DirXML-RACF-omvs-procusermax

The maximum number of processes the user is allowed to have active at the same time.

DirXML-RACF-omvs-program

The pathname of the user’s UNIX shell program.

DirXML-RACF-omvs-threadsmax

The maximum number of pthread_created threads the user can have concurrently active.

DirXML-RACF-omvs-uid

The user’s UID.

DirXML-RACF-operations

OPERATIONS attribute for the user.

DirXML-RACF-operparm-altgrp

Console group used in recovery.

DirXML-RACF-operparm-auth

User’s authority to issue operator commands.

DirXML-RACF-operparm-auto

Whether the user’s MCS console session receives messages which have been automated by the Message Processing Facility (MPF) in the sysplex.

DirXML-RACF-operparm-cmdsys

The system to which commands from the user’s MCS console session are sent.

DirXML-RACF-operparm-dom

Which delete operator message (DOM) requests the user’s MCS console session receives.

DirXML-RACF-operparm-key

User’s name for DISPLAY CONSOLES,KEY.

DirXML-RACF-operparm-level

Message levels the user’s MCS console session receives.

DirXML-RACF-operparm-logcmdresp

Whether command responses the user’s MCS console session are logged.

DirXML-RACF-operparm-mform

Message format for the user’s MCS console session.

DirXML-RACF-operparm-migid

Whether a migration ID is assigned to the user’s MCS console session.

DirXML-RACF-operparm-monitor

Which information is displayed at the user’s MCS console session when monitoring jobs, TSO sessions, or data set status.

DirXML-RACF-operparm-mscope

Systems from which the user’s MCS console session receives messages not directed to a specific console.

DirXML-RACF-operparm-routcode

Routing codes of messages the user’s MCS console session receives.

DirXML-RACF-operparm-storage

Amount of storage in the TSO/E address space that can be used for message queuing to the user’s MCS console session.

DirXML-RACF-operparm-ud

Whether the user’s MCS console session receives undelivered messages.

DirXML-RACF-ovm-fsroot

The pathname for the file system root.

DirXML-RACF-ovm-home

The user’s home directory pathname.

DirXML-RACF-ovm-program

The pathname of the user’s UNIX shell program.

DirXML-RACF-ovm-uid

The user’s UID.

DirXML-RACF-password-interval

The number of days a password remains valid for the user.

DirXML-RACF-password-passdate

Date the user’s password expires.

DirXML-RACF-proxy-binddn

Distinguished name (DN) the z/OS LDAP Server uses when acting as a proxy.

DirXML-RACF-proxy-bindpw

Password the z/OS LDAP Server uses when acting as a proxy.

DirXML-RACF-proxy-ldaphost

URL of the LDAP server the z/OS LDAP Server contacts when acting as a proxy.

DirXML-RACF-restricted

Whether global access checking is bypassed when resource access checking is performed for the user, and neither ID(*) on the access list nor the UACC allow access.

DirXML-RACF-resumedate

Future date the user will be allowed access to the system again.

DirXML-RACF-revoked

Whether the user is prevented from accessing the system.

DirXML-RACF-revokedate

Future date the user will be prevented from accessing the system.

DirXML-RACF-seclabel

The user’s default security label.

DirXML-RACF-seclevel

The user’s security level.

DirXML-RACF-special

SPECIAL attribute for the user.

DirXML-RACF-tso-acctnum

Default TSO account number on the TSO/E logon panel.

DirXML-RACF-tso-command

Command to be run during TSO/E logon.

DirXML-RACF-tso-dest

Default SYSOUT destination.

DirXML-RACF-tso-holdclass

Default hold class.

DirXML-RACF-tso-jobclass

Default job class.

DirXML-RACF-tso-maxsize

The maximum region size the user can request at logon.

DirXML-RACF-tso-msgclass

Default message class.

DirXML-RACF-tso-proc

Default logon procedure on the TSO/E logon panel.

DirXML-RACF-tso-seclabel

User’s security label.

DirXML-RACF-tso-size

Minimum region size if not requested at logon.

DirXML-RACF-tso-sysoutclass

Default SYSOUT class.

DirXML-RACF-tso-unit

Default UNIT name for allocations.

DirXML-RACF-tso-userdata

Installation-defined data for the user.

DirXML-RACF-uaudit

Whether RACF performs audit logging for the user.

DirXML-RACF-userid

The user’s user ID.

DirXML-RACF-when-days

Days of the week when the user is allowed to log on to the system.

DirXML-RACF-when-time

Hours of the day when the user is allowed to log on to the system.

DirXML-RACF-workattr-waaccnt

Account number for APPC/MVS processing.

DirXML-RACF-workattr-waaddr1

Address line 1 for SYSOUT delivery.

DirXML-RACF-workattr-waaddr2

Address line 2 for SYSOUT delivery.

DirXML-RACF-workattr-waaddr3

Address line 3 for SYSOUT delivery.

DirXML-RACF-workattr-waaddr4

Address line 4 for SYSOUT delivery.

DirXML-RACF-workattr-wabldg

Building for SYSOUT delivery.

DirXML-RACF-workattr-wadept

Department for SYSOUT delivery.

DirXML-RACF-workattr-waname

User name for SYSOUT delivery.

DirXML-RACF-workattr-waroom

Room for SYSOUT delivery.

Table A-2 Class User Attributes

Attribute Name

Case Sensitive

Multivalue

Naming

Read-Only

Required

Type

DirXML-RACF-adsp

false

false

false

false

false

state

DirXML-RACF-auditor

false

false

false

false

false

state

DirXML-RACF-category

false

true

false

false

false

string

DirXML-RACF-cics-opclass

false

true

false

false

false

int

DirXML-RACF-cics-opident

false

false

false

false

false

string

DirXML-RACF-cics-opprty

false

false

false

false

false

int

DirXML-RACF-cics-timeout

false

false

false

false

false

string

DirXML-RACF-cics-xrfsoff

false

false

false

false

false

string

DirXML-RACF-clauth

false

true

false

false

false

string

DirXML-RACF-data

false

false

false

false

false

string

DirXML-RACF-dce-autologin

false

false

false

false

false

state

DirXML-RACF-dce-dcename

false

false

false

false

false

string

DirXML-RACF-dce-homecell

false

false

false

false

false

string

DirXML-RACF-dce-homeuuid

false

false

false

false

false

string

DirXML-RACF-dce-uuid

false

false

false

false

false

string

DirXML-RACF-dfltgrp

false

false

false

false

false

dn

DirXML-RACF-dfp-dataappl

false

false

false

false

false

string

DirXML-RACF-dfp-dataclas

false

false

false

false

false

string

DirXML-RACF-dfp-mgmtclas

false

false

false

false

false

string

DirXML-RACF-dfp-storclas

false

false

false

false

false

string

DirXML-RACF-eim-ldapprof

false

false

false

false

false

string

DirXML-RACF-groups

false

true

false

false

false

dn

DirXML-RACF-grpacc

false

false

false

false

false

state

DirXML-RACF-kerb-encrypt-des

false

false

false

false

false

state

DirXML-RACF-kerb-encrypt-des3

false

false

false

false

false

state

DirXML-RACF-kerb-encrypt-desd

false

false

false

false

false

state

DirXML-RACF-kerb-kerbname

false

false

false

false

false

string

DirXML-RACF-kerb-maxtktlfe

false

false

false

false

false

int

DirXML-RACF-language-primary

false

false

false

false

false

string

DirXML-RACF-language-secondary

false

false

false

false

false

string

DirXML-RACF-lnotes-sname

false

false

false

false

false

string

DirXML-RACF-model

false

false

false

false

false

string

DirXML-RACF-name

false

false

false

false

false

string

DirXML-RACF-nds-uname

false

false

false

false

false

string

DirXML-RACF-netview-consname

false

false

false

false

false

string

DirXML-RACF-netview-ctl

false

false

false

false

false

string

DirXML-RACF-netview-domains

false

true

false

false

false

string

DirXML-RACF-netview-ic

false

false

false

false

false

string

DirXML-RACF-netview-msgrecvr

false

false

false

false

false

state

DirXML-RACF-netview-ngmfadmn

false

false

false

false

false

state

DirXML-RACF-netview-ngmfvspn

false

false

false

false

false

string

DirXML-RACF-netview-opclass

false

true

false

false

false

string

DirXML-RACF-omvs-assizemax

false

false

false

false

false

int

DirXML-RACF-omvs-cputimemax

false

false

false

false

false

int

DirXML-RACF-omvs-fileprocmax

false

false

false

false

false

int

DirXML-RACF-omvs-home

false

false

false

false

false

string

DirXML-RACF-omvs-mmapareamax

false

false

false

false

false

int

DirXML-RACF-omvs-procusermax

false

false

false

false

false

int

DirXML-RACF-omvs-program

false

false

false

false

false

string

DirXML-RACF-omvs-threadsmax

false

false

false

false

false

int

DirXML-RACF-omvs-uid

false

false

false

false

false

int

DirXML-RACF-operations

false

false

false

false

false

state

DirXML-RACF-operparm-altgrp

false

false

false

false

false

string

DirXML-RACF-operparm-auth

false

false

false

false

false

string

DirXML-RACF-operparm-auto

false

false

false

false

false

state

DirXML-RACF-operparm-cmdsys

false

false

false

false

false

string

DirXML-RACF-operparm-dom

false

false

false

false

false

string

DirXML-RACF-operparm-key

false

false

false

false

false

string

DirXML-RACF-operparm-level

false

false

false

false

false

string

DirXML-RACF-operparm-logcmdresp

false

false

false

false

false

string

DirXML-RACF-operparm-mform

false

false

false

false

false

string

DirXML-RACF-operparm-migid

false

false

false

false

false

state

DirXML-RACF-operparm-monitor

false

false

false

false

false

string

DirXML-RACF-operparm-mscope

false

true

false

false

false

string

DirXML-RACF-operparm-routcode

false

false

false

false

false

string

DirXML-RACF-operparm-storage

false

false

false

false

false

int

DirXML-RACF-operparm-ud

false

false

false

false

false

state

DirXML-RACF-ovm-fsroot

true

false

false

false

false

string

DirXML-RACF-ovm-home

true

false

false

false

false

string

DirXML-RACF-ovm-program

true

false

false

false

false

string

DirXML-RACF-ovm-uid

false

false

false

false

false

int

DirXML-RACF-password-interval

false

false

false

false

false

string

DirXML-RACF-password-passdate

false

false

false

true

false

string

DirXML-RACF-proxy-binddn

false

false

false

false

false

string

DirXML-RACF-proxy-bindpw

false

false

false

false

false

string

DirXML-RACF-proxy-ldaphost

false

false

false

false

false

string

DirXML-RACF-restricted

false

false

false

false

false

state

DirXML-RACF-resumedate

false

false

false

false

false

string

DirXML-RACF-revoked

false

false

false

false

false

state

DirXML-RACF-revokedate

false

false

false

false

false

string

DirXML-RACF-seclabel

false

false

false

false

false

string

DirXML-RACF-seclevel

false

false

false

false

false

string

DirXML-RACF-special

false

false

false

false

false

state

DirXML-RACF-tso-acctnum

false

false

false

false

false

string

DirXML-RACF-tso-command

false

false

false

false

false

string

DirXML-RACF-tso-dest

false

false

false

false

false

string

DirXML-RACF-tso-holdclass

false

false

false

false

false

string

DirXML-RACF-tso-jobclass

false

false

false

false

false

string

DirXML-RACF-tso-maxsize

false

false

false

false

false

int

DirXML-RACF-tso-msgclass

false

false

false

false

false

string

DirXML-RACF-tso-proc

false

false

false

false

false

string

DirXML-RACF-tso-seclabel

false

false

false

false

false

string

DirXML-RACF-tso-size

false

false

false

false

false

int

DirXML-RACF-tso-sysoutclass

false

false

false

false

false

string

DirXML-RACF-tso-unit

false

false

false

false

false

string

DirXML-RACF-tso-userdata

false

false

false

false

false

string

DirXML-RACF-uaudit

false

false

false

false

false

state

DirXML-RACF-userid

false

false

true

true

true

string

DirXML-RACF-when-days

false

false

false

false

false

string

DirXML-RACF-when-time

false

false

false

false

false

string

DirXML-RACF-workattr-waaccnt

false

false

false

false

false

string

DirXML-RACF-workattr-waaddr1

false

false

false

false

false

string

DirXML-RACF-workattr-waaddr2

false

false

false

false

false

string

DirXML-RACF-workattr-waaddr3

false

false

false

false

false

string

DirXML-RACF-workattr-waaddr4

false

false

false

false

false

string

DirXML-RACF-workattr-wabldg

false

false

false

false

false

string

DirXML-RACF-workattr-wadept

false

false

false

false

false

string

DirXML-RACF-workattr-waname

false

false

false

false

false

string

DirXML-RACF-workattr-waroom

false

false

false

false

false

string

Table A-3 Class Group Attribute Descriptions

Attribute Name

Description

DirXML-RACF-data

Installation-defined data for the group profile.

DirXML-RACF-dfp-dataappl

DFP data application for group data sets.

DirXML-RACF-dfp-dataclas

Default data class for group data sets.

DirXML-RACF-dfp-mgmtclas

Default management class for group data sets.

DirXML-RACF-dfp-storclas

Default storage class for group data sets.

DirXML-RACF-group

The name of the group.

DirXML-RACF-model

Group’s model data set profile.

DirXML-RACF-omvs-gid

The group’s OMVS GID.

DirXML-RACF-ovm-gid

The group’s OVM GID.

DirXML-RACF-owner

Owner of the group.

DirXML-RACF-subgroup

Subordinate groups of the group.

DirXML-RACF-supgroup

Superior group of the group.

DirXML-RACF-termuacc

Whether RACF uses universal access authority for a terminal when checking whether a user in the group is authorized to access a terminal.

DirXML-RACF-tme-roles

TME roles that reference the group.

DirXML-RACF-universal

Whether this is a universal group.

Table A-4 Class Group Attributes

Attribute Name

Case Sensitive

Multivalue

Naming

Read-Only

Required

Type

DirXML-RACF-data

false

false

false

false

false

string

DirXML-RACF-dfp-dataappl

false

false

false

false

false

string

DirXML-RACF-dfp-dataclas

false

false

false

false

false

string

DirXML-RACF-dfp-mgmtclas

false

false

false

false

false

string

DirXML-RACF-dfp-storclas

false

false

false

false

false

string

DirXML-RACF-group

false

false

true

false

true

string

DirXML-RACF-model

false

false

false

false

false

string

DirXML-RACF-omvs-gid

false

false

false

false

false

int

DirXML-RACF-ovm-gid

false

false

false

false

false

int

DirXML-RACF-owner

false

false

false

false

false

string

DirXML-RACF-subgroup

false

true

false

true

false

dn

DirXML-RACF-supgroup

false

false

false

false

false

dn

DirXML-RACF-termuacc

false

false

false

false

false

state

DirXML-RACF-tme-roles

false

true

false

false

false

string

DirXML-RACF-universal

false

false

false

false

false

state