> So we will have control over what gets executed

As others have pointed out, you are exposing yourself to risks that you will
have to manage. MVS would be willing to take on some of that management for
you, but you are overriding that facility.

You need to make absolutely sure of who has the ability to write into every
single dataset used as a load or parameter or script library by every single
thing called by your STC.

Charles


-----Original Message-----
From: IBM Mainframe Discussion List [mailto:IBM-MAIN@LISTSERV.UA.EDU] On
Behalf Of Robin Atwood
Sent: Tuesday, May 16, 2017 12:10 AM
To: IBM-MAIN@LISTSERV.UA.EDU
Subject: Re: ATTACH with RSAPF=YES

Thanks to everyone for replying, I would never realised you had to flip
JSCBAUTH from the macro documentation. 
The actual business requirement is that we run Rexx execs that call ISPF
services on behalf of workstation users running an IDE. The STC doing this
must run authorised because it communicates with a comms task via
cross-memory services. So we will have control over what gets executed. This
is still very much an experiment, I am not sure it will actually work.

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

Reply via email to