Download SOLVE:EPS User's Guide
Transcript
Command Security User Exit Terminate Terminate Terminate is called when SOLVE:EPS is terminating and signals the end of the need for SOLVE:EPS command security. It is entered with the parameter list pointer in R1. The parameter list contains the following values: +0 Pointer to command security environment returned by the main entry point. This call has no return. IsEachSignonUnique The IsEachSignonUnique call answers whether this interface wants each user command access to SOLVE:EPS (for example, signon WTD message) is to be considered a unique user instance or not. The response from this function determines what the VerifyUser function may see in the pointer to the token, VERIPSEC in CMD$CRTY. An affirmative response guarantees that it will always be NULL (0); a negative response means that it may not be NULL. It is entered with the parameter list pointer in R1. The parameter list contains the following values: +0 Pointer to command security environment returned by the main entry point. This function sets the return code in R15, which must be one of the following: 0 NO, user command accesses after an initial access are to be considered instances of the initial access. 1 YES, each command access is to be considered an independent, unique access, regardless of whether the same user has other command access already or not. Sample SAF Based Command Security Exit T07XXCS2 T07XXCS2 is a sample security exit distributed to illustrate how an installation may want to implement a SAF based command security exit. What follows describes how one would implement this exit as is. As shipped, T07XXCS2 provides for user verification and resource authorization checking. User verification is the process of matching a User ID to a password. Resources authorization is the process of determining a verified user’s authority to access a particular resource. T07XXCS2 uses a RACROUTE REQUEST=VERIFY invocation to enable user verification. If RACROUTE returns a value of 0 in R15, the user is considered verified and the verification instance is now represented by a control block called an ACEE. The ACEE is subsequently used as input to resource authorization. If RACROUTE returns a non-zero value in R15, user verification is considered to have failed. RACROUTE REQUEST=AUTH is used by T07XXCS2 to check a verified user’s authorization to access a particular resource for a particular purpose. If RACROUTE returns a value not greater than 4 in R15, the resource access is allowed; otherwise, it is denied. A table in T07XXCS2 at label ALVLCMDV establishes a correlation between a SOLVE:EPS command and RACROUTE parameters ENTITY and ATTR. The table is searched sequentially. For instance, the SOLVE:EPS command START INPROCESSOR myinp maps to an entity name of INP.MYINP and an attribute of Update. RACROUTE would check if the user was authorized to resource INP.MYINP for update access. If a match in table ALVLCMDV is not found, T07XXCS2 bypasses the RACROUTE invocation and denies authorization. User Exits A – 49
Related documents