vmbigot Beginner

Joined: 17 Jun 2004 Posts: 36 Topics: 14 Location: westminster, california
|
Posted: Wed May 03, 2006 1:16 pm Post subject: racf special attribute |
|
|
We have a security administrator that only creates new RACF user profiles for one particular group profile. I currently have this security admin defined with the SPECIAL attribute. This attribute gives this administrator access to ALL RACF functions, including changing user passwords, etc.
I need to limit this administrator to only allow him/her the authority to add/change users defined to a particular RACF group. For example, RACF group PFUSER has the authority to logon to CICS and execute transactions within CICS. PFUSER does not have the authority to update system datasets or logon to TSO. How can I limit this administrator to only the PFUSER group?
Thanks,
vmbigot
BTW, I tried researching the RACF manuals but fell asleep within 10 seconds!  _________________ Inside every older man is a young boy asking this question. What the heck happened?!? |
|