Need to delete unnecesary profiles



All about SAF, RACF, encryption, Firewall, Risk assessment and integrity concepts

Need to delete unnecesary profiles

Postby gdchipi » Fri Oct 25, 2013 10:49 pm

I was asked to delete unnecesary RACF rule profiles (with no alias no datasets and no user connected). I understand that means to identity genrral profiles without alias, datasets and users but is difficult to understand how to find out them. Could you help me?
gdchipi
 
Posts: 14
Joined: Sat Sep 08, 2012 12:56 am
Has thanked: 0 time
Been thanked: 0 time

Re: Need to delete unnecesary profiles

Postby prino » Sat Oct 26, 2013 2:27 am

If you don't know how to administrate RACF you have no business administrating RACF...
Robert AH Prins
robert.ah.prins @ the.17+Gb.Google thingy
User avatar
prino
 
Posts: 641
Joined: Wed Mar 11, 2009 12:22 am
Location: Vilnius, Lithuania
Has thanked: 3 times
Been thanked: 29 times

Re: Need to delete unnecesary profiles

Postby steve-myers » Sat Oct 26, 2013 6:10 am

prino wrote:If you don't know how to administrate RACF you have no business administrating RACF...
Take it easy on the guy, Robert. I suspect every mature RACF data base has many effectively expired profiles in it. Deleting them is relatively easy, though time consuming. Identifying them, though, is another story.

First, you have to define exactly what you mean by an "expired" profile. I can think of a number of definitions; none of which are very easy to track down. This is the first thing gdchipi has to do. Gdchipi is probably going to run into some political problems here. The terminology in the first post here seems to indicate he has a problem with the scope.

Having defined what is meant by an "expired" profile gdchipi needs to find them. I have a couple ideas here, but I'm not even going to research them. It will mean a lot of work.

Having identified the profiles, gdchipi needs to delete them. Not so easy, but not so difficult, either.

Good luck.
steve-myers
Global moderator
 
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Has thanked: 4 times
Been thanked: 243 times

Re: Need to delete unnecesary profiles

Postby prino » Sun Oct 27, 2013 2:37 am

steve-myers wrote:
prino wrote:If you don't know how to administrate RACF you have no business administrating RACF...
Take it easy on the guy, Robert.

A RACF administrator posting on "A Help & Support Forum for Mainframe Beginners and Students", gimme a break...

How long would we let someone like this rummage around on "that" system?
Robert AH Prins
robert.ah.prins @ the.17+Gb.Google thingy
User avatar
prino
 
Posts: 641
Joined: Wed Mar 11, 2009 12:22 am
Location: Vilnius, Lithuania
Has thanked: 3 times
Been thanked: 29 times

Re: Need to delete unnecesary profiles

Postby steve-myers » Sun Oct 27, 2013 6:11 am

Agreed. It's probably safe to look, but an adult should probably oversee profile deletions.

Juveniles have to start somewhere Robert, and adults are hard to find in the security business. Most employers won't hire an adult anyway. Too expensive. Even an adult is going to goof.
steve-myers
Global moderator
 
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Has thanked: 4 times
Been thanked: 243 times

Re: Need to delete unnecesary profiles

Postby gdchipi » Tue Oct 29, 2013 12:21 am

I need to identify rule profiles (I understand means groups) having no user-datasets connected and having no alias. Is hard for me identify groups without alias. Do you know the way?
gdchipi
 
Posts: 14
Joined: Sat Sep 08, 2012 12:56 am
Has thanked: 0 time
Been thanked: 0 time

Re: Need to delete unnecesary profiles

Postby Robert Sample » Tue Oct 29, 2013 12:35 am

If you have a tool like SAS or Easytrieve available, you might want to extract a sequential file from the RACF data base using IRRDBU00 and use the various record types to identify what you can get rid of. I don't recall which manual in the Security bookshelf talks about IRRDBU00 and its output record types, but it should be easy enough to find. If you don't have such a tool available, you are going to have a very tough time doing what you want to accomplish since you'll be looking for negatives (things that are not connected) instead of positives.
Robert Sample
Global moderator
 
Posts: 3720
Joined: Sat Dec 19, 2009 8:32 pm
Location: Dubuque, Iowa, USA
Has thanked: 1 time
Been thanked: 279 times

Re: Need to delete unnecesary profiles

Postby gdchipi » Tue Oct 29, 2013 12:49 am

Yes: I can use REXX to get the info from the database but I couldnt identify a record identifying the ALIAS there.
gdchipi
 
Posts: 14
Joined: Sat Sep 08, 2012 12:56 am
Has thanked: 0 time
Been thanked: 0 time

Re: Need to delete unnecesary profiles

Postby steve-myers » Tue Oct 29, 2013 6:28 am

The usual meaning of the word "alias" in this context is an alias entry for a userid or group name in the master catalog. "Alias" is not a RACF concept. The only way I know to test if an alias exists is to execute a LISTCAT ENT('xxx') IDCAMS command and check the return code. If the return code is 0, there is an alias entry, unless it is for something else.
steve-myers
Global moderator
 
Posts: 2105
Joined: Thu Jun 03, 2010 6:21 pm
Has thanked: 4 times
Been thanked: 243 times

Re: Need to delete unnecesary profiles

Postby gdchipi » Thu Oct 31, 2013 3:12 am

Thank you very much. I could identify the alias. Thanks again.
gdchipi
 
Posts: 14
Joined: Sat Sep 08, 2012 12:56 am
Has thanked: 0 time
Been thanked: 0 time

Next

Return to Mainframe Security