<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://m204wiki.rocketsoftware.com/index.php?action=history&amp;feed=atom&amp;title=SirSafe_control_of_access_to_passwords</id>
	<title>SirSafe control of access to passwords - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://m204wiki.rocketsoftware.com/index.php?action=history&amp;feed=atom&amp;title=SirSafe_control_of_access_to_passwords"/>
	<link rel="alternate" type="text/html" href="https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;action=history"/>
	<updated>2026-05-13T19:46:00Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94948&amp;oldid=prev</id>
		<title>JAL: /* Model 204 Security Environments */ add link</title>
		<link rel="alternate" type="text/html" href="https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94948&amp;oldid=prev"/>
		<updated>2016-12-07T20:31:19Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Model 204 Security Environments: &lt;/span&gt; add link&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 20:31, 7 December 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l52&quot;&gt;Line 52:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 52:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Each of the security manager interfaces supported by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; implements a&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Each of the security manager interfaces supported by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; implements a&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;default set of parameters, and it also provides a facility for customizing&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;default set of parameters, and it also provides a facility for customizing&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;parameters that can be selected by the &amp;lt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;code&lt;/del&gt;&amp;gt;SECPLIST&amp;lt;/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;code&lt;/del&gt;&amp;gt; User&amp;amp;nbsp;0 parameter.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;parameters that can be selected by the &amp;lt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;var&lt;/ins&gt;&amp;gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;SECPLIST &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;parameter|SECPLIST]]&lt;/ins&gt;&amp;lt;/&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;var&lt;/ins&gt;&amp;gt; User&amp;amp;nbsp;0 parameter.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In order to determine if a particular Online is operating under the control of a&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In order to determine if a particular Online is operating under the control of a&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;security manager, and to determine the specific parameters in effect, you can&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;security manager, and to determine the specific parameters in effect, you can login as a system manager and execute the following command:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;login as a system manager and execute the following command:&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;AUTHCTL VIEW&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;AUTHCTL VIEW&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/p&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l66&quot;&gt;Line 66:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 65:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;RACF&amp;lt;/th&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;RACF&amp;lt;/th&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;td&amp;gt;Now known as the IBM Security Server, RACF is an IBM Program product. The HLQ parameter is &amp;lt;code&amp;gt;GROUP&amp;lt;/code&amp;gt;, which has a default value of &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&quot;&lt;/del&gt;M204RACF&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&quot;&lt;/del&gt;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;td&amp;gt;Now known as the IBM Security Server, RACF is an IBM Program product. The HLQ parameter is &amp;lt;code&amp;gt;GROUP&amp;lt;/code&amp;gt;, which has a default value of &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;code&amp;gt;&lt;/ins&gt;M204RACF&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/code&amp;gt;&lt;/ins&gt;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;TOPSECRET&amp;lt;/th&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;TOPSECRET&amp;lt;/th&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;td&amp;gt;CA-Top Secret is marketed by Computer Associates. The HLQ parameter is &amp;lt;code&amp;gt;ACID&amp;lt;/code&amp;gt;, which has a default value of &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&quot;&lt;/del&gt;M204TOPS&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&quot;&lt;/del&gt;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;td&amp;gt;CA-Top Secret is marketed by Computer Associates. The HLQ parameter is &amp;lt;code&amp;gt;ACID&amp;lt;/code&amp;gt;, which has a default value of &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;code&amp;gt;&lt;/ins&gt;M204TOPS&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/code&amp;gt;&lt;/ins&gt;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;ACF2&amp;lt;/th&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;ACF2&amp;lt;/th&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>JAL</name></author>
	</entry>
	<entry>
		<id>https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94935&amp;oldid=prev</id>
		<title>JAL: link repair</title>
		<link rel="alternate" type="text/html" href="https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94935&amp;oldid=prev"/>
		<updated>2016-12-06T23:18:44Z</updated>

		<summary type="html">&lt;p&gt;link repair&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 23:18, 6 December 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l169&quot;&gt;Line 169:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 169:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Activating and deactivating SirSafe==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Activating and deactivating SirSafe==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Until version 7.5 of Model 204, &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; was distributed as a component of&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Until version 7.5 of Model 204, &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; was distributed as a component of&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;the &amp;lt;var class=&quot;product&quot;&amp;gt;[[&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;SirMods&lt;/del&gt;]]&amp;lt;/var&amp;gt; product.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;the &amp;lt;var class=&quot;product&quot;&amp;gt;[[&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Sirius Mods&lt;/ins&gt;]]&amp;lt;/var&amp;gt; product.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thereafter, it is a member of the [[RKTools]] product.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Thereafter, it is a member of the [[RKTools]] product.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>JAL</name></author>
	</entry>
	<entry>
		<id>https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94793&amp;oldid=prev</id>
		<title>JAL: /* Model 204 Security Environments */</title>
		<link rel="alternate" type="text/html" href="https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94793&amp;oldid=prev"/>
		<updated>2016-12-01T01:31:49Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Model 204 Security Environments&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:31, 1 December 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l42&quot;&gt;Line 42:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 42:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A Security Environment consists of:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A Security Environment consists of:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;ul&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;ul&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;li&amp;gt;An &amp;lt;code&amp;gt;interface&amp;lt;/code&amp;gt; between &amp;lt;var class=&quot;product&quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;li&amp;gt;An &amp;lt;code&amp;gt;interface&amp;lt;/code&amp;gt; between &amp;lt;var class=&quot;product&quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; and a particular security manager &amp;lt;/li&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;and a particular security manager &amp;lt;/li&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;li&amp;gt;Certain &amp;lt;code&amp;gt;security parameters&amp;lt;/code&amp;gt; that are specific to the interface &amp;lt;/li&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;li&amp;gt;Certain &amp;lt;code&amp;gt;security parameters&amp;lt;/code&amp;gt; that are specific to the interface &amp;lt;/li&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l49&quot;&gt;Line 49:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 48:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Detailed information about how to install and configure a security interface for&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Detailed information about how to install and configure a security interface for&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; can be found in the&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; can be found in the&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Security interfaces overview|Model 204 security interfaces]] pages.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Security interfaces overview|Model&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;amp;nbsp;&lt;/ins&gt;204 security interfaces]] pages.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Each of the security manager interfaces supported by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; implements a&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Each of the security manager interfaces supported by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; implements a&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>JAL</name></author>
	</entry>
	<entry>
		<id>https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94745&amp;oldid=prev</id>
		<title>Admin: 1 revision: SirSafe pages</title>
		<link rel="alternate" type="text/html" href="https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94745&amp;oldid=prev"/>
		<updated>2016-11-30T21:32:41Z</updated>

		<summary type="html">&lt;p&gt;1 revision: SirSafe pages&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 21:32, 30 November 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94744&amp;oldid=prev</id>
		<title>JAL: link repair</title>
		<link rel="alternate" type="text/html" href="https://m204wiki.rocketsoftware.com/index.php?title=SirSafe_control_of_access_to_passwords&amp;diff=94744&amp;oldid=prev"/>
		<updated>2016-11-30T21:08:00Z</updated>

		<summary type="html">&lt;p&gt;link repair&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; system manager uses the &amp;lt;var&amp;gt;[[SirSafe command and function reference#logctl enhancements|LOGCTL]]&amp;lt;/var&amp;gt; command to maintain database passwords in [[Storing security information (CCASTAT)|CCASTAT]].&lt;br /&gt;
Then &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; maps the individual file and group entries in CCASTAT into resources that may be controlled&lt;br /&gt;
by a system security manager, such as RACF.&lt;br /&gt;
Judicious use of naming standards simplifies the division of responsibility&lt;br /&gt;
between the &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; system manager and a system security officer.&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
When &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; is active, it alters the process of verifying passwords for Private and Semipublic files and groups.&lt;br /&gt;
When CCASTAT is scanned for a matching password during the file or group open process,&lt;br /&gt;
an additional step is added for each entry that matches the password entered by the end-user.&lt;br /&gt;
Before the access rights associated with the entry are granted, a system security manager is&lt;br /&gt;
used to verify that the user has &amp;lt;code&amp;gt;READ&amp;lt;/code&amp;gt; access to that entry in CCASTAT.&lt;br /&gt;
If the user doesn&amp;#039;t have &amp;lt;code&amp;gt;READ&amp;lt;/code&amp;gt; access, the entry is skipped, and CCASTAT processing continues as if the passwords did not match.&lt;br /&gt;
Thus, an end user could know a password, but be denied its use.&lt;br /&gt;
&lt;br /&gt;
File or group password entries with the same password and different privileges&lt;br /&gt;
can be used to implement very flexible security schemes.&lt;br /&gt;
Password entries conveying &amp;quot;strong&amp;quot; access rights should be entered into&lt;br /&gt;
CCASTAT with index characters that collate low, such as blank or &amp;lt;code&amp;gt;A&amp;lt;/code&amp;gt;.&lt;br /&gt;
An entry with the same password and weaker privileges (like read-only)&lt;br /&gt;
could follow with a higher collating index, such as &amp;lt;code&amp;gt;1&amp;lt;/code&amp;gt;.&lt;br /&gt;
Then the same password could give two different users different access rights,&lt;br /&gt;
depending upon rules enforced by a system security manager.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; also enhances control over when an end user is allowed to change the password for a particular file or group CCASTAT entry.&lt;br /&gt;
Whenever &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; prompts for a password, the end user may enter the password value,&lt;br /&gt;
followed by a colon (&amp;lt;tt&amp;gt;:&amp;lt;/tt&amp;gt;) and a replacement password value.&lt;br /&gt;
If the password is matched, then the replacement password value may be&lt;br /&gt;
used to overlay the password value in the CCASTAT entry.&lt;br /&gt;
Without &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt;, a particular end user must be authorized to change &amp;lt;i&amp;gt;all&amp;lt;/i&amp;gt; file or group passwords or to change &amp;lt;i&amp;gt;none&amp;lt;/i&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; adds another level of checking before end users are allowed to change a file or group password.&lt;br /&gt;
The end user must first have &amp;lt;code&amp;gt;READ&amp;lt;/code&amp;gt; access to the particular CCASTAT entry,&lt;br /&gt;
then if a replacement password value was provided, &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; checks for &amp;lt;code&amp;gt;WRITE&amp;lt;/code&amp;gt; access&lt;br /&gt;
to the CCASTAT entry.&lt;br /&gt;
If the end user has &amp;lt;code&amp;gt;WRITE&amp;lt;/code&amp;gt; access, the password is updated.&lt;br /&gt;
Otherwise, the update request is rejected.&lt;br /&gt;
This facility can prevent the accidental updating of a password shared by many people.&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;b id=&amp;quot;msecenv&amp;quot;&amp;gt;&amp;lt;/b&amp;gt;Model 204 Security Environments==&lt;br /&gt;
Use of &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; requires an active &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; &amp;lt;b&amp;gt;Security Environment&amp;lt;/b&amp;gt;.&lt;br /&gt;
A Security Environment consists of:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;An &amp;lt;code&amp;gt;interface&amp;lt;/code&amp;gt; between &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt;&lt;br /&gt;
and a particular security manager &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;Certain &amp;lt;code&amp;gt;security parameters&amp;lt;/code&amp;gt; that are specific to the interface &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
Detailed information about how to install and configure a security interface for&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; can be found in the&lt;br /&gt;
[[Security interfaces overview|Model 204 security interfaces]] pages.&lt;br /&gt;
&lt;br /&gt;
Each of the security manager interfaces supported by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; implements a&lt;br /&gt;
default set of parameters, and it also provides a facility for customizing&lt;br /&gt;
parameters that can be selected by the &amp;lt;code&amp;gt;SECPLIST&amp;lt;/code&amp;gt; User&amp;amp;nbsp;0 parameter.&lt;br /&gt;
In order to determine if a particular Online is operating under the control of a&lt;br /&gt;
security manager, and to determine the specific parameters in effect, you can&lt;br /&gt;
login as a system manager and execute the following command:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;AUTHCTL VIEW&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
If an interface is active, &amp;lt;var&amp;gt;[[SirSafe command and function reference#auctlvw|AUTHCTL VIEW]]&amp;lt;/var&amp;gt; identifies it and list its current parameters.&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; adapts a parameter from each type of interface to form the High Level Qualifier (HLQ) used for mapping CCASTAT entries into virtual data set names.&lt;br /&gt;
The parameter used for each interface and the interface defaults are as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;thJustBold&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr class=&amp;quot;head&amp;quot;&amp;gt;&amp;lt;th nowrap&amp;gt;Interface type&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Description and HLQ source&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;RACF&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;Now known as the IBM Security Server, RACF is an IBM Program product. The HLQ parameter is &amp;lt;code&amp;gt;GROUP&amp;lt;/code&amp;gt;, which has a default value of &amp;quot;M204RACF&amp;quot;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;TOPSECRET&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;CA-Top Secret is marketed by Computer Associates. The HLQ parameter is &amp;lt;code&amp;gt;ACID&amp;lt;/code&amp;gt;, which has a default value of &amp;quot;M204TOPS&amp;quot;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;ACF2&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;CA-ACF2 is marketed by Computer Associates. The HLQ is formed by appending the value of the &amp;lt;code&amp;gt;RESOURCE&amp;lt;/code&amp;gt; field to the constant &amp;lt;code&amp;gt;R&amp;lt;/code&amp;gt;. Thus, the default is &amp;lt;code&amp;gt;R204&amp;lt;/code&amp;gt;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Mapping CCASTAT entries to data sets==&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; maps each file or group entry in CCASTAT to a corresponding data set name.&lt;br /&gt;
When an end-user needs to access a particular CCASTAT entry (for example,&lt;br /&gt;
the entry contains a match for a file or group open password entered by the user), the active&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; security interface is used to determine if the data set corresponding to that CCASTAT&lt;br /&gt;
entry could be read (or written) by the user.&lt;br /&gt;
Note that no attempt is made to open the particular data set, and the data set does not need to exist.&lt;br /&gt;
&lt;br /&gt;
The data set names used by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; for verifying CCASTAT access have four levels:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;The High Level Qualifier is determined by the active &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt;&lt;br /&gt;
security interface as previously described. &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;The second qualifier is the string &amp;lt;code&amp;gt;FILE&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;GROUP&amp;lt;/code&amp;gt;,&lt;br /&gt;
depending upon whether a file or group is being opened. &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;The third level is the name of the file or group. &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;The final level is determined by the index character for the current CCASTAT entry.&lt;br /&gt;
It will contain the constant string &amp;lt;code&amp;gt;INDEX&amp;lt;/code&amp;gt;, followed by the&lt;br /&gt;
actual index character, if it is alphanumeric, or else by the two-character&lt;br /&gt;
hexadecimal representation of the index character. &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following example shows the data set names used by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; to check access for&lt;br /&gt;
some corresponding file password entries, assuming that the RACF interface is active&lt;br /&gt;
with the default RACF Control Group Name (&amp;lt;code&amp;gt;M204RACF&amp;lt;/code&amp;gt;):&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;&amp;lt;b&amp;gt;file      index      corresponding &amp;quot;dataset&amp;quot; name&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;:ALANPROC      ...   M204RACF.FILE.ALANPROC.INDEX40&lt;br /&gt;
:ALANPROC A    ...   M204RACF.FILE.ALANPROC.INDEXA&lt;br /&gt;
:ALANPROC 1    ...   M204RACF.FILE.ALANPROC.INDEX1&lt;br /&gt;
:ASDF          ...   M204RACF.FILE.ASDF.INDEX40&lt;br /&gt;
:BACKUP        ...   M204RACF.FILE.BACKUP.INDEX40&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;b id=&amp;quot;ssmodes&amp;quot;&amp;gt;&amp;lt;/b&amp;gt;SirSafe modes for CCASTAT==&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; is controlled by parameters contained in a special CCASTAT entry&lt;br /&gt;
maintained by the &amp;lt;code&amp;gt;AUTHCTL&amp;lt;/code&amp;gt; system manager command (see [[SirSafe command and function reference#autha|AUTHCTL A SIRSAFE]]).&lt;br /&gt;
The special entry includes a list of allowed &amp;lt;b&amp;gt;security environments&amp;lt;/b&amp;gt; and&lt;br /&gt;
a &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; &amp;lt;b&amp;gt;mode&amp;lt;/b&amp;gt; specification as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table class=&amp;quot;thJustBold&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;OPTIONAL&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;A CCASTAT that is set to &amp;lt;var&amp;gt;OPTIONAL&amp;lt;/var&amp;gt; mode may be used by any &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; load module, with or without &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; support and regardless of the current security environment.&lt;br /&gt;
However, &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; will only control access to file and group entries in an optional CCASTAT when the current security environment matches one of those specified in the special &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; entry.&lt;br /&gt;
&amp;lt;p class=&amp;quot;note&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note:&amp;lt;/b&amp;gt; &amp;lt;var&amp;gt;OPTIONAL&amp;lt;/var&amp;gt; mode only activates a subset of the &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; functionality. &amp;lt;/p&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;th&amp;gt;REQUIRED&amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;td&amp;gt;A CCASTAT that is set to &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; mode may only be opened by a &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; load module with &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; installed and with a security&lt;br /&gt;
environment that matches one of those specified in the special &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt;entry.&lt;br /&gt;
The &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; mode activates additional features of &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt;.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; attribute can be used to ensure that a specific security environment&lt;br /&gt;
is used to control access to the file and group entries in CCASTAT.&lt;br /&gt;
This is especially important when the value of passwords is widely known&lt;br /&gt;
and &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; provides the security instead of relying on secrecy.&lt;br /&gt;
&lt;br /&gt;
==Support of &amp;quot;visible&amp;quot; passwords==&lt;br /&gt;
When &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; is &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; for a CCASTAT, then no file or grouppassword can be used&lt;br /&gt;
unless the end-user is allowed access to the CCASTAT entry containing the password.&lt;br /&gt;
As explained earlier in this section, one benefit of this is that&lt;br /&gt;
different end-users can be given different privileges when using the&lt;br /&gt;
same password to open the same file or group.&lt;br /&gt;
Another benefit is that passwords themselves can be freely shared and distributed,&lt;br /&gt;
that is, they do not need to be kept a secret.&lt;br /&gt;
&lt;br /&gt;
When &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; is &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; for a CCASTAT, it supports so-called &amp;lt;b&amp;gt;visible&amp;lt;/b&amp;gt; file and group passwords.&lt;br /&gt;
Extensions to the &amp;lt;var&amp;gt;LOGCTL&amp;lt;/var&amp;gt;, &amp;lt;var&amp;gt;LOGFILE&amp;lt;/var&amp;gt;, and &amp;lt;var&amp;gt;LOGGRP&amp;lt;/var&amp;gt; commands&lt;br /&gt;
allow visible passwords to be entered, maintained, and displayed in clear text.&lt;br /&gt;
This can greatly simplify management of multiple passwords for a particular&lt;br /&gt;
file or group, since there is no guessing about the password value.&lt;br /&gt;
&lt;br /&gt;
Ordinary (invisible) file or group passwords are maintained by the &amp;lt;var&amp;gt;LOGCTL&amp;lt;/var&amp;gt; command, using&lt;br /&gt;
either a colon (&amp;lt;tt&amp;gt;:&amp;lt;/tt&amp;gt;) to indicate a file entry or a&lt;br /&gt;
comma (&amp;lt;tt&amp;gt;,&amp;lt;/tt&amp;gt;) to indicate a group entry.&lt;br /&gt;
Visible entries are indicated by a different pair of special characters:&lt;br /&gt;
The &amp;quot;greater than&amp;quot; symbol (&amp;lt;tt&amp;gt;&amp;gt;&amp;lt;/tt&amp;gt;) indicates a visible file entry, and&lt;br /&gt;
the &amp;quot;plus sign&amp;quot; (&amp;lt;tt&amp;gt;+&amp;lt;/tt&amp;gt;) indicates a visible group entry.&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;var&amp;gt;LOGFILE&amp;lt;/var&amp;gt; and &amp;lt;var&amp;gt;LOGGRP&amp;lt;/var&amp;gt; commands are extended to display the password value for visible entries, else a field of asterisks:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;&amp;lt;b&amp;gt;LOGFILE PROCFILE&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&amp;gt;PROCFILE A THEMAN    X&amp;#039;BFFF&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
:PROCFILE B ********  X&amp;#039;0761&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
&amp;gt;PROCFILE 4 THEMAN    X&amp;#039;0221&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
In the example above, there are three password table entries for the file &amp;lt;code&amp;gt;PROCFILE&amp;lt;/code&amp;gt;.&lt;br /&gt;
Two of them, for the same password, are visible.&lt;br /&gt;
In this example, a user in the &amp;quot;file managers&amp;quot; group could get access to the&lt;br /&gt;
slot associated with index character &amp;lt;code&amp;gt;A&amp;lt;/code&amp;gt;, while everyone else could get access&lt;br /&gt;
to the slot associated with index character &amp;lt;code&amp;gt;4&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Activating and deactivating SirSafe==&lt;br /&gt;
Until version 7.5 of Model 204, &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; was distributed as a component of&lt;br /&gt;
the &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;[[SirMods]]&amp;lt;/var&amp;gt; product.&lt;br /&gt;
Thereafter, it is a member of the [[RKTools]] product.&lt;br /&gt;
&lt;br /&gt;
Once &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; is installed, the&lt;br /&gt;
&amp;lt;var&amp;gt;[[SirSafe command and function reference#autha|AUTHCTL A SIRSAFE]]&amp;lt;/var&amp;gt; command may be used to activate &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; for the current CCASTAT.&lt;br /&gt;
&lt;br /&gt;
Activation adds a special control entry that contains the execution parameters for &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt;.&lt;br /&gt;
If the &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; keyword is present, the version number of CCASTAT will be altered.&lt;br /&gt;
This prevents the CCASTAT from being opened by &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; load modules&lt;br /&gt;
without &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; support or without the proper security environment.&lt;br /&gt;
&lt;br /&gt;
For example, the following command would activate &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; as &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt;&lt;br /&gt;
and usable only with RACF, using the default value for the &amp;lt;var&amp;gt;GROUP&amp;lt;/var&amp;gt; parameter:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;AUTHCTL A SIRSAFE REQUIRED MVSRW RACF=M204RACF&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The contents of the &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; special entry may be displayed by the&lt;br /&gt;
&amp;lt;var&amp;gt;[[SirSafe command and function reference#authlst|AUTHCTL LIST SIRSAFE]]&amp;lt;/var&amp;gt; command.&lt;br /&gt;
The current &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; parameters can be replaced using the&lt;br /&gt;
&amp;lt;var&amp;gt;[[SirSafe command and function reference#authc|AUTHCTL C SIRSAFE]]&amp;lt;/var&amp;gt; command, or&lt;br /&gt;
deleted using the &amp;lt;var&amp;gt;[[SirSafe command and function reference#authd|AUTHCTL D SIRSAFE]]&amp;lt;/var&amp;gt; command.&lt;br /&gt;
&amp;lt;p class=&amp;quot;note&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note:&amp;lt;/b&amp;gt; If any visible passwords have been stored, they must&lt;br /&gt;
all be deleted before&lt;br /&gt;
the &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; environment can be deleted or changed from &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt; to &amp;lt;var&amp;gt;OPTIONAL&amp;lt;/var&amp;gt;.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;b id=&amp;quot;idccsta&amp;quot;&amp;gt;&amp;lt;/b&amp;gt;Identifying file/group CCASTAT entries==&lt;br /&gt;
Most &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; password tables contain a jumble of entries that have accumulated over time.&lt;br /&gt;
Frequently a system manager just adds a new password when emergency access is required for a file.&lt;br /&gt;
Without visible passwords, it is very easy to lose track of which password corresponds to a particular index character.&lt;br /&gt;
Confusion is especially likely when a password is added that has the same value&lt;br /&gt;
as one that occurs earlier in the collating sequence.&lt;br /&gt;
&lt;br /&gt;
SirSafe implements an extension to the &amp;lt;var&amp;gt;LOGFILE&amp;lt;/var&amp;gt; and &amp;lt;var&amp;gt;LOGGRP&amp;lt;/var&amp;gt; commands that allows the&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; system manager to create a map of the relationship between password values and index characters.&lt;br /&gt;
It can also be used to identify password entries that have duplicate password values.&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;var&amp;gt;PWDLOCATE&amp;lt;/var&amp;gt; keyword can be used with the &amp;lt;var&amp;gt;LOGFILE&amp;lt;/var&amp;gt; or &amp;lt;var&amp;gt;LOGGRP&amp;lt;/var&amp;gt; command to&lt;br /&gt;
cause the system to prompt the user for a password value to be &amp;quot;ANDed&amp;quot; with the&lt;br /&gt;
other search conditions.&lt;br /&gt;
The &amp;lt;var&amp;gt;PWDLOCATE&amp;lt;/var&amp;gt; option could be used to diagnose a problem concerning a failure to achieve the desired access:&lt;br /&gt;
Suppose a System Manager added a password with the value &amp;lt;code&amp;gt;WRITE&amp;lt;/code&amp;gt; with index&lt;br /&gt;
character &amp;lt;code&amp;gt;A&amp;lt;/code&amp;gt;, but the user reports the password &amp;quot;didn&amp;#039;t work.&amp;quot;&lt;br /&gt;
&amp;lt;var&amp;gt;LOGCTL&amp;lt;/var&amp;gt; shows the following:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;&amp;lt;b&amp;gt;logfile alanproc&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;:ALANPROC   ******** X&amp;#039;0201&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
:ALANPROC A ******** X&amp;#039;BFFF&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
:ALANPROC 1 ******** X&amp;#039;0CCC&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You could use the &amp;lt;var&amp;gt;PWDLOCATE&amp;lt;/var&amp;gt; option to identify all of the password&lt;br /&gt;
entries that have the password value &amp;lt;code&amp;gt;WRITE&amp;lt;/code&amp;gt;:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;&amp;lt;b&amp;gt;logfile pwdlocate alanproc&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;*** M204.0347: PASSWORD&lt;br /&gt;
:ALANPROC   ******** X&amp;#039;0201&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
:ALANPROC A ******** X&amp;#039;BFFF&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
This example shows that the CCASTAT entry for file &amp;lt;code&amp;gt;ALANPROC&amp;lt;/code&amp;gt; with the blank index character&lt;br /&gt;
also has the password value &amp;lt;code&amp;gt;WRITE&amp;lt;/code&amp;gt;, and because it occurs first in the collating sequence, it is being used.&lt;br /&gt;
&lt;br /&gt;
For more information about the &amp;lt;var&amp;gt;PWDLOCATE&amp;lt;/var&amp;gt; option, see [[SirSafe command and function reference#pwdloca|Selecting entries by password]].&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;b id=&amp;quot;mvcstat&amp;quot;&amp;gt;&amp;lt;/b&amp;gt;Moving file/group CCASTAT entries==&lt;br /&gt;
Because &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; controls access to individual file or group entries in CCASTAT, the&lt;br /&gt;
index character for a password entry is very important.&lt;br /&gt;
Naming conventions should be used to enable a few generic dataset rules to cover many files and groups.&lt;br /&gt;
&lt;br /&gt;
A good convention to start with includes the following:&lt;br /&gt;
&amp;lt;ol&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Reserve the blank character for system manager emergency use. &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;Reserve a few other low-collating characters (like A through E)&lt;br /&gt;
for mapping unrecognized passwords, so &amp;quot;warning rules&amp;quot; can be used to identify their users. &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;Reserve the next few characters (like F through H) for all high-power file management passwords. &amp;lt;/li&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;li&amp;gt;Reserve index characters that collate high, like numeric digits,&lt;br /&gt;
for less-powerful, &amp;quot;public&amp;quot; passwords. &amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ol&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;Model&amp;amp;nbsp;204&amp;lt;/var&amp;gt; password tables contain entries that were allocated in a haphazard fashion with no particular order.&lt;br /&gt;
In order to assist with a migration to a more orderly structure, &amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt;&lt;br /&gt;
implements a facility for copying a file or group password entry from its current slot to a slot with a different index character.&lt;br /&gt;
The &amp;lt;var&amp;gt;[[SirSafe command and function reference#logctlr|LOGCTL R]]&amp;lt;/var&amp;gt; command is used to&lt;br /&gt;
copy the identified file or group CCASTAT entry.&lt;br /&gt;
If the specified entry is located, the user is prompted for the index&lt;br /&gt;
character to be used for the copy:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;&amp;lt;b&amp;gt;logctl r :procfile&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;amp;#42;**  M204.0374: ENTER INDEX CHARACTER FOR REPLICATE&lt;br /&gt;
&amp;lt;b&amp;gt;4&amp;lt;/b&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&amp;gt;PROCFILE 4 ******** X&amp;#039;BFFF&amp;#039;   0,   0,   0,   0,   0,    ALL&lt;br /&gt;
&amp;amp;#42;**  M204.0376: PARAMETERS ACCEPTED&lt;br /&gt;
&amp;amp;#42;**  M204.0345: CCASTAT UPDATED&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p class=&amp;quot;note&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Note:&amp;lt;/b&amp;gt; The sequence of &amp;lt;code&amp;gt;LOGCTL R&amp;lt;/code&amp;gt; followed by &amp;lt;code&amp;gt;LOGCTL D&amp;lt;/code&amp;gt; moves a file or group entry in CCASTAT. &amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==&amp;lt;b id=&amp;quot;secure&amp;quot;&amp;gt;&amp;lt;/b&amp;gt;Enhanced SECURE command==&lt;br /&gt;
&amp;lt;var class=&amp;quot;product&amp;quot;&amp;gt;SirSafe&amp;lt;/var&amp;gt; extends the &amp;lt;var&amp;gt;[[SirSafe command and function reference#SECURE command enhancements|SECURE]]&amp;lt;/var&amp;gt; command so that a file or group can be set to&lt;br /&gt;
open only when SirSafe is active (that is, the CCASTAT mode may be &amp;lt;var&amp;gt;OPTIONAL&amp;lt;/var&amp;gt;&lt;br /&gt;
or &amp;lt;var&amp;gt;REQUIRED&amp;lt;/var&amp;gt;, but there must be a valid security environment).&lt;br /&gt;
This provides an easier-to-manage facility for helping to avoid exposures to&lt;br /&gt;
counterfeited password tables.&lt;br /&gt;
This facility is activated with the following command:&lt;br /&gt;
&amp;lt;p class=&amp;quot;code&amp;quot;&amp;gt;SECURE FILE SIRSAFE&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The CCASTAT modes are described in [[#ssmodes|SirSafe modes for CCASTAT]], and&lt;br /&gt;
the security environment is described in [[#msecenv|Model 204 Security Environments]].&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
{{Template:SirSafe topic list}}&lt;br /&gt;
&lt;br /&gt;
[[Category:SirSafe]]&lt;/div&gt;</summary>
		<author><name>JAL</name></author>
	</entry>
</feed>