On Thursday, 08/10/2006 at 07:24 AST, "Imler, Steven J" 
<[EMAIL PROTECTED]> wrote:
  
> You can use the VM:Tape USERSECR EXIT (assembler only) for  a non-RACF 
solution.

If you can issue CMS commands in the exit, then you can custom-build a 
RACF solution.  The program would have to take as input the VM userid, the 
tape id, and requested access.  Then build a RACROUTE call with the needed 
parameters.  Et voila!

> Also, VM:Tape does have a RACF interface via PRODUCT RACF  VM:Tape 
CONFIG FILE 
> record.  The VM:Tape SVM would need all appropriate  authorizations to 
issue 
> RACROUTE calls ... and of course you will have to code  *all* the 
permits.

If RACF defers to you, what do you do?  Also, you can use generic profiles 
to, for example, deny access to all tapes except those specifically 
defined and PERMITed.

Alan Altmark
z/VM Development
IBM Endicott

Reply via email to