AUDISPD-ZOS-REMOTE(8) (NAME) audispd-zos-remote - z/OS (SYNOPSIS) audispd-zos-remote [ config-file ] (DESCRIPTION) audispd-zos-remote (Audit) . auditd(8) IBM Tivoli Directory Server (ITDS) (Remote Audit) z/OS SMF (Service Management Facility) . SMF SMF (SMF Mapping) . auditd(8) . /etc/audit/plugins.d/audispd-zos-remote.conf /etc/audit/plugins.d ( auditd(8) ). /etc/audit/zos-remote.conf . zos-remote.conf(5) . (OPTIONS) config-file /etc/audit/zos-remote.conf . (SIGNALS) audispd-zos-remote SIGTERM SIGHUP ( auditd(8)) : SIGHUP audispd-zos-remote (flush) . SIGTERM . audispd-zos-remote . IBM z/OS ITDS RACF (IBM z/OS ITDS Server and RACF configuration) IBM z/OS v1R8 ( ) IBM Tivoli Directory Server (ITDS) . z/OS z/OS V1R8.0-9.0 Integrated Security Services Enterprise Identity Mapping (EIM) Guide and Reference (http://publibz.boulder.ibm.com/cgi-bin/bookmgr_OS390/FRAMESET/EIMA1140/CCONTENTS?DT=20070827115119) "2.0 - Working with remote services" . ITDS (Enable ITDS to process Remote Audit requests) ITDS ITDS READ FACILITY IRR.AUDITX ( R_Auditx ) . STARTED (started procedure) ITDS . ITDS ITDSUSER TSO RACF ITDS : TSO Commands: READ ITDSUSER FACILITY IRR.AUDITX rdefine FACILITY IRR.RAUDITX uacc(none) permit IRR.RAUDITX class(FACILITY) id(ITDSUSER) access(READ) / RACF (Create/enable RACF user ID to perform Remote Audit requests) z/OS RACF RACF ( zos-remote.conf(5) ) . READ FACILITY IRR.LDAP.REMOTE.AUDIT . BINDUSER TSO RACF : TSO Commands: BINDUSER rdefine FACILITY IRR.LDAP.REMOTE.AUDIT uacc(none) permit IRR.LDAP.REMOTE.AUDIT class(FACILITY) id(BINDUSER) access(READ) @LINUX RACF (Add @LINUX Class to RACF) audispd-zos-remote @LINUX CDT Class ( SYSCALL AVC PATH ...) CDT Resource Class . RACF Dynamic CDT @LINUX . TSO : TSO Commands: CDT @LINUX rdefine cdt @LINUX cdtinfo(posit(493) FIRST(alpha,national,numeric,special) OTHER(alpha,national,numeric,special) RACLIST(REQUIRED) case(asis) generic(allowed) defaultuacc(none) maxlength(246)) setr classact(cdt) setr raclist(cdt) setr raclist(cdt) refresh setr classact(@LINUX) setr raclist(@LINUX) setr generic(@LINUX) @LINUX (Add profiles to the @LINUX Class) CDT ( wildcards ). : TSO Commands: AVC ( ): rdefine @LINUX * uacc(none) audit(none(read)) rdefine @LINUX AVC uacc(none) audit(all(read)) setr raclist(@LINUX) refresh TSO Commands: ( ): rdefine @LINUX * uacc(none) audit(all(read)) setr raclist(@LINUX) refresh (best match) . RACF . . SMF (SMF Mapping) ITDS SMF . ( SMF ) : (Link Value) (network-byte order). . (Violation) (0) - False (Event Code) (2) - Authorization () (Event Qualifier) (0) - Success success=yes res=success (3) - Fail success=no res=failed (1) - Info . (Class) @LINUX (Resource) : SYSCALLAVCPATHCWD . (Log String) RACF : Remote audit request from RACFUSER. Linux (hostname.localdomain):USER_AUTH (Data Field List) relocates fieldname=value relocate (Application specific Data) . ( root 0). relocate (Date And Time Security Event Occurred) ctime(3) . (ERRORS) syslog ( DAEMON) . z/OS . : NOTREQ - No logging required ( ) RACF - @LINUX . IBM z/OS ITDS RACF (IBM z/OS ITDS Server and RACF configuration) . UNDETERMINED - Undetermined result . @LINUX @LINUX . IBM z/OS ITDS RACF (IBM z/OS ITDS Server and RACF configuration) . UNAUTHORIZED - The user does not have authority the R_auditx service ITDS READ FACILITY IRR.AUDITX . IBM z/OS ITDS RACF (IBM z/OS ITDS Server and RACF configuration) . UNSUF_AUTH - The user has insufficient authority for the requested function RACF ( zos-remote.conf(5) ) FACILITY IRR.LDAP.REMOTE.AUDIT . IBM z/OS ITDS RACF (IBM z/OS ITDS Server and RACF configuration) . (BUGS) (best-effort) z/OS ( ) . (FILES) /etc/audit/plugins.d/audispd-zos-remote.conf /etc/audit/zos-remote.conf (SEE ALSO) auditd(8) zos-remote.conf(5). (AUTHOR) Klaus Heinrich Kiwi IBM Oct 2007 AUDISPD-ZOS-REMOTE(8)