Database tables and columns for TSS
config
Field | Format | Description | Value |
---|---|---|---|
system | Text | LPAR name | |
type | Text | Entry type | SYSTEM, PASSWORD TSSPARM entries are configuration entries from the TSSPARM file. TSSPARMC are current live values of the TSSPARM settings (that is, they might have changed since Top Secret started). SMF, DISA USS CONSOLE, TSO, CNGRP |
parm | Text | Parameter | DISA - CLASSIFIED SMF - ACTIVE, INTVAL, JWT, MAXDORM, MEMBER, MEMLIMIT, SID, STATUS, STC, STCDETAIL, STCINTVAL, STCTYPES, SWT, SYNCVAL, SYS, SYSDETAIL, SYSINTVAL, SYSTYPES, TSO, TSODETAIL, TSOINTVAL, TSOTYPES, TWT SYSTEM - ALLOWUSERKEYCSA, AUTHTSF, ESM, IPLDATE, IPLTIME TSSPARM - ADSP, AUTH, AUTOERASE, BACKUP, CPF, CPFNODES, DATE, DEBUG, DL1B, DOWN, EXIT, FACILITY, HPBPW, INACTIVE, INSTDATA, IOTRACE, JES, JOBACID, LOG, MFA, MODE, MSUSPEND, NEWPW, PRODUCTS, PTHRESH, PWEXP, RECOVER, SECTRACE, SHRFILE, SUBACID, SWAP, TAPE, TEMPDS, TIMER, VTHRESH TSSPARMC - Audit File, ADABAS, ADMINBY, ADSP, AES_ENCRYPTION, AESCACHE, AESENC, AUTH, AUTOERASE, BACKUP, CACHE, CANCEL, CATADELPROT, CHOWN_RESTRICTED, CMDNUM, CPF, CPFrecfl, CPFAUTOGID, CPFAUTOUID, CPFLISTMULT, CPFRCVUND, CPFTARGET, CPFWAIT, DATE, DB2FAC, DEBUG, DFLTRNGG, DFLTRNGU, DL1B, DOWN, DUFPGM, ETRLOG, ETROPTS, EXIT, EXPAND_COUNTER, EXPDAYS, FACMODE, FACSTOR, FSACCESS, GENNDT, GENSMSG, GOSETGID, GTRACE, HFSACL, HFSSEC, HPBPW, Id=PRIMARY, IMS, INACTIVE, INSTDATA, IOTRACE, JCT, JES, JESNODE, JOBACID, KERBLVL, Last changed, LARGE_VSAM_RECORD, LOG, LUUPDONCE, MATCHLIM, MAX_ACID_SIZE, MAXKEYSIZE, MFA, MFACCESS, MIRROR, MODE, MODLUSER, MSUSPEND, NEW_PASSWORD, NEWPHRASE, NEWPW, NJEUSR, NPPTHRESH, NPWRTHRESH, OMVSGRP, OMVSUSR, OPTIONALS, PDSPROT, PHRASEONLY, PPEXP, PPHIST, PRODUCTS, PROFINTERVAL, PROPXREP, PSWDPHRASE, PTHRESH, PTKRESCK, PWADMIN, PWEXP, PWHIST, PWVERIFY, PWVIEW, Recovery File, RCACHE, RDT2BYTE, Security File, SDNSIZE, SECCACHE, SECTRACE, SMFTYPE, STATUS, SUBACID, SWAP, SYSOUT, TAPE, TEMPDS, TEXTTSS, TIMELOCK, TIMER, TNG MONITOR, TSSCMDOPTION, UNIQUSER, UNIXOPTS, Vsam File, VSAM_DIGICERT, VSAMCAT, VTHRESH USS - STARTUPPROC, STEPLIBLIST, SUPERUSER, TTYGROUP, USERIDALIAS CONSOLE - MCS TSO - UADS CNGRP - GROUPNAME |
value | Text | Parameter value | DISA - CLASSIFIED - YES | NO SYSTEM - ESM - RACF | TSS | ACF2 CONSOLE - MCS - attributesOfMasterConsole TSO - UADS - useridFromSYS1.UADS CNGRP - GROUPNAME - member |
Examples:
- Type=DISA, parm=CLASSIFIED, value=YES | NO
The value indicates whether this instance should be treated as a classified system. This field can be queried by a compliance query. Manually set these values in the configuration member, in the SPMParms block. - Type=SYSTEM, parm=ESM, value=RACF | TSS | ACF2
The value indicates the external security manager. This field can be queried by a compliance query. - Type=SYSTEM, parm=IPLDATE, value=yyyy-mm-dd
The value indicates the date of last IPL. - Type=SYSTEM, parm=IPLTIME, value=hh:mm:ss
The value indicates the time of last IPL. - Type=CONSOLE, parm=MCS, value=attributesOfMasterConsole
Value examples: NAME(BMC23700) STATUS(ACT-BMC2) AUTH(MASTER) DEV(3700) LOGON(OPTIONAL) USERID(N/A) ROUT(ALL)
console
Field | Format | Description | Value |
---|---|---|---|
name | Text | Console name | |
stflg | Single hexadecimal digit | Status flag | |
status | Text | Representation of stflg with Y or N corresponding to 0 or 1 For example, X'F0' is YYYYNNNN. | Status bit settings:
|
key | Text | User-assigned key | |
sysnm | Text | System name | |
rtflg | Single hexadecimal digit | Routing flag | |
routing | Text | Representation of rtflg with Y or N corresponding to 0 or 1 For example, X'F0' is YYYYNNNN. | Routing bit settings:
|
domflg | Single hexadecimal digit | DOM settings | |
dom | Text | Representation of domflg with Y or N corresponding to 0 or 1 For example, X'F0' is YYYYNNNN. | DOM bit settings:
|
mlvlflg | Single hexadecimal digit | MLVL flags, a single hexadecimal digit | |
mlvl | Text | Representation of mlvlflg with Y or N corresponding to 0 or 1 For example, X'F0' is YYYYNNNN. | MLVL bit settings:
|
authflg | Single hexadecimal digit | Console AUTH settings, a single hexadecimal digit | |
auth | Text | Representation of authlflg with Y or N corresponding to 0 or 1 For example, X'F0' is YYYYNNNN. | AUTH bit settings:
|
terminal | Text | Eight-character terminal name | |
jobnm | Text | Eight-character job name | |
rout | Text | Route codes for this console | All, None, or specific codes as a 16-character hexadecimal value |
sens (sensitive data sets)
Field | Format | Description | Value |
---|---|---|---|
apf | Text | Is APF authorized? | Y or blank |
audit | Text | Profile audit settings | Success/Failures |
cat | Text | Is data set cataloged? | Y or blank |
cdate | Text | Creation Date | yyyy-mm-dd |
dsn | Text | Sensitive Data set Name | |
fqg | Text | Fully Qualified Generic data set? | Y or blank |
idstar | Text | ID(*) access | N, R, U, C, A, E, T |
level | Text | Profile level | 1-99 |
profile | Text | Protecting profile | |
rdate | Text | Last reference date | yyyy-mm-dd |
sms | Text | Is SMS managed? | Y or blank |
system | Text | LPAR Name of Reporting system | |
type | Text | Data set type | ACS, APF, CSF, DUMP, ESMC, HFS, IODF, IPL, JES2, LINK, LPA, MCAT, PAGE, PARM, RACF, SMF, SMS, TFS, UADS, UCAT, USER, VIO, ZDT, ZFS, PSWD, REXX, VTAM For a description of each type of data set, see the Data set type descriptionstable. |
uacc | Text | Data set UACC | N, R, U, C, A, E, T |
volser | Text | Data set volume | |
warn | Text | WARN attribute? | Y or blank |
summary
Field | Format | Description | Value |
---|---|---|---|
System | Text | System the compliance check was run on | |
Reference | Text | Reference as defined in the RULES(INDEX) data set | |
Rule | Text | Rule name from the RULES(INDEX) data set | |
ESM | Text | External security manager on the system | RACF, TSS, or ACF2 |
Category | Text | Defined in the RULES(INDEX) data set | |
Priority | Text | Defined in the RULES(INDEX) data set | |
Failures | Text | Number of failures discovered by the query | |
Lastrun | Text | Date and time the query was last run | dd mm HH:MM:SS |
Lastrun | Text | Date and time the query will next run | dd mm HH:MM:SS |
Description | Text | Description from the RULES(INDEX) data set |
tss
Field | Format | Description | Value |
---|---|---|---|
system | Text | System Name | |
date | Text | Date | yyyy-mm-dd |
time | Text | Time | hh:mm |
user | Text | user ACID | |
portofentry | Text | Port of Entry | |
jobname | Text | Job name | |
rc | Text | Return Code | |
ac | Text | Abend Code | |
type | Text | Command Type | |
flag1 | Text | ACEE flag1 | |
flag2 | Text | ACEE flag2 | |
flag3 | Text | ACEE flag3 | |
command | Text | Command Text |
tss_acid
Field | Format | Description | Value |
---|---|---|---|
acid | Text | ACID name | |
asuspend | Integer | user has ASUSPEND | |
audit | Integer | user has AUDIT | |
console | Integer | user has CONSOLE | |
credate | Text | Creation Date | yyyy-mm-dd |
cretime | Text | Creation Time | hh:mm |
dept | Text | Department | |
div | Text | Division | |
dufupd | Integer | user has DUFUPD | |
dufxtr | Integer | user has DUFXTR | |
expires | Text | user has an expiration date | |
gap | Integer | user is globally administered | |
human | Text | user is human - Not currently used | |
instdata | Text | user's INSTDATA | |
language | Text | language preference code | |
lastcnt | Integer | Last Use Count | |
lastcpu | Text | Last Use CPU | |
lastdate | Text | Last Use Date | yyyy-mm-dd |
lastfac | Text | Last Use Facility | |
lasttime | Text | Last Use Time | hh:mm |
lds | Integer | user has LDS attribute | |
lockfac | Text | Lock Time Facility | |
locktime | Integer | Lock Time minutes | |
mastfac | Text | Master Facility | |
matchlim | Integer | Limit Audit Activity | |
moddate | Text | Modified Date | yyyy-mm-dd |
mode | Text | Operating Mode | |
modtime | Text | Modified Time | hh:mm |
mro | Integer | user has MRO | |
multipw | Integer | user has MULTIPW | |
name | Text | User's Name | |
noadsp | Integer | user has NOADSP | |
noats | Integer | user has NOATS | |
nodsnchk | Integer | user has NODSNCHK | |
nolcfchk | Integer | user has NOLCFCHK | |
noomvsdf | Integer | user has NOOMVSDF | |
nopwchg | Integer | user has NOPWCHG | |
norefres | Integer | user has NOREFRES | |
noreschk | Integer | user has NORESCHK | |
nosubchk | Integer | user has NOSUBCHK | |
nosuspen | Integer | user has NOSUSPEN | |
novmdchk | Integer | user has NOVMDCHK | |
novolchk | Integer | user has NOVOLCHK | |
oidcard | Integer | user has OIDCARD | |
parent | Text | Parent - not currently used | |
phraseexpirydate | Text | Passphrase Expiry Date | |
phraseinterval | Text | Passphrase Interval | |
psuspend | Integer | user has PSUSPEND | |
pswdphr | Integer | user has a Password Phrase | |
pwexpirydate | Text | Password Expiry Date | yyyy-mm-dd |
pwfacility | Text | Facility if user has MultiPW | |
pwinterval | Text | Password interval | |
rstdacc | Integer | user has RSTDACC | |
scope | Text | user's authority scope | |
size | integer | ACID size | |
suspend | Integer | user is suspended | |
suspended | Text | date suspension ends | |
timezone | Text | user's timezone | |
trace | Integer | diagnostic trace is active | |
tsompw | Integer | user has multiple UADS passwords | |
type | Text | ACID type | |
vmsfsdir | Text | Currently unused | |
vsuspend | Integer | user has VSUSPEND | |
xsuspend | Integer | user has XSUSPEND | |
zonename | Text | user's zone ACID | |
zone | Text | user's zone name |
tss_admin_auths
Field | Format | Description | Value |
---|---|---|---|
acid | Text | ACID | |
authority | Text | Admin authority | |
authority_type | Text | Admin authority tyoe |
tss_group_connects
Field | Format | Description | Value |
---|---|---|---|
acid | Text | ACID | |
grp | Text | Group Name | |
until | Text | Expiry date | yyyy-mm-dd |
tss_profile_connects
Field | Format | Description | Value |
---|---|---|---|
acid | Text | ACID | |
profile | Text | Profile name | |
until | Text | Expiry date | yyyy-mm-dd |
tss_rdt
Field | Format | Description | Value |
---|---|---|---|
class | Text | Class Name | |
defacc | Text | Resource Default Access | |
posit | Text | Posit value |
tss_rdt_access
Field | Format | Description | Value |
---|---|---|---|
class | Text | Class Name | |
level | Text | Resource Access Level | |
mask | Text | Resource Access Mask |
tss_rdt_attribute
Field | Format | Description | Value |
---|---|---|---|
class | Text | Class Name | |
attribute | Text | RDT Attribute |
tss_started_tasks
Field | Format | Description | Value |
---|---|---|---|
stc | Text | Started Task Name | |
stcacid | Text | Associated ACID | |
stcact | Text | Operator Accountability |
tss_xa_access
Field | Format | Description | Value |
---|---|---|---|
acid | Text | ACID | |
class | Text | Resource class | |
resource | Text | Resource Name | |
owner | Text | Resource Owner | |
until | Text | Expiry date/time | |
quoted | Integer | Resource has quotes | |
facility | Text | Facility Name | |
access | Text | Access Level | |
action | Text | Associated actions | Any of the following actions (as defined in CA Top Secret documentation): FAIL, DENY, AUDIT, NOTIFY, PASSWORD, NODSN, EXIT, REVERIFY, or VMPRIV |