Security check in CZPOSTPR

Discussion of Co:Z sftp, a port of OpenSSH sftp for z/OS
Post Reply
robschramm
Posts: 10
Joined: Tue Apr 21, 2009 3:35 am

Security check in CZPOSTPR

Post by robschramm »

I am looking to perform a security check while I am in CZPOSTPR. But it just dawned on me that I am not in a typical address space. And I am wondering what if anything I would need to do differently to issue a RACROUTE VERIFY.
dovetail
Site Admin
Posts: 2022
Joined: Thu Jul 29, 2004 12:12 pm

Re: Security check in CZPOSTPR

Post by dovetail »

The Co:Z Server does run in an OMVS address, but that is not particularly special in this case.

Be advised, however, that the Co:Z Server by default runs in an address space with normal user priviledges (the user that is logged on), and is not APF authorized. It is possible to use the sample "relink-sftp-server.sh" shell script to relink the Co:Z sftp-server executable as APF authorized.

Without APF authorization, *some* features of RACROUTE will fail - check the documentation.
robschramm
Posts: 10
Joined: Tue Apr 21, 2009 3:35 am

Re: Security check in CZPOSTPR

Post by robschramm »

Ok. I expected the non-APF nature. I am fairly sure that APF will not be needed for checking authorization of the existing user ID with "what I hope is" an existing ACEE. I am off to RTFM.
Post Reply