Defining a DBC control point resource profile
The DBC subsystem and its components automatically call the SAF router to check user authorization to various services.
These services are identified by internal functional control points and are externally associated with a resource name. You control user access to the DBC component services by granting or denying authorization to the resource names that are associated with these internal functional control points. To control access to these services, you must define these resource names to the ESM.
To define a DBC control point resource profile
Define the resource profile (that is, the resource name) to the RACF ESM by using one or more RDEFINE FACILITY commands.
- Activate the resource class by issuing one of the following commands:
- SETROPTS CLASSACT(FACILITY)
- SETROPTS CLASSACT(FACILTY) RACLIST(FACILITY)(to maintain profiles in memory)
(optional) Enable generic profile checking for the FACILITY class:
SETROPTS GENERIC(FACILITY)
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*