Your Browser is not longer supported

Please use Google Chrome, Mozilla Firefox or Microsoft Edge to view the page correctly
Loading...

{{viewport.spaceProperty.prod}}

SET-PRIVILEGE Grant global privileges

Domain:

SECURITY-ADMINISTRATION

Privileges:

SECURITY-ADMINISTRATION

This command serves to grant a user ID global privileges.

It is not possible to assign privileges or privilege sets to a user ID which possesses the privilege SECURITY-ADMINISTRATION on the pubset specified in the command.

The command takes effect for the entire system, i.e. the user ID can use the global privileges assigned in the command, only if the command is issued for a user ID on the home pubset.

The command does not affect any jobs under this user ID that are active at the time of command entry; it becomes effective only after the next LOGON under this user ID.

SET-PRIVILEGE

PRIVILEGE = *PRIVILEGE-SET(...) / list-poss(64): <text>


*PRIVILEGE-SET(...)



|

PRIVILEGE-SET-NAME = list-poss(20): <name 1..8>

,USER-IDENTIFICATION = <name 1..8>

,PUBSET = *HOME / <cat-id 1..4>

PRIVILEGE =
The privilege to be assigned to a user ID. This operand is mandatory. Either individual privileges or the names of privilege sets may be specified. The individual privileges are described in the section "Management of privileges".

PRIVILEGE = *PRIVILEGE-SET(...)
Specifies one or more privilege sets.

PRIVILEGE-SET-NAME = list-poss(20): <name 1..8>
Privilege set that is to be assigned to the user ID, or a list of privilege sets.

PRIVILEGE = list-poss(64): <text>
Privilege that is to be assigned to a user ID. See "Functional overview" for possible privileges. Exceptions: TSOS and SECURITY-ADMINISTRATION.

USER-IDENTIFICATION = <name 1..8>
User ID which is to be granted the specified privilege.

PUBSET = *HOME / <cat-id 1..4>
Pubset on which the specified privilege is to be entered for the user ID.

PUBSET = *HOME
The specified privilege is to be entered on the home pubset. This causes the assigned privilege(s) to be valid for the entire system.

PUBSET = <cat-id 1..4>
The entry is made on the specified pubset.

Notes
  • The USER-ADMINISTRATION privilege cannot be assigned (either individually or as part of a privilege set) to a user ID that has already been designated as a group administrator on the pubset specified via the PUBSET operand.

  • Assigning the SAT-FILE-MANAGEMENT privilege (or a privilege set which includes this privilege) to a user ID causes the SAT function to be activated for this user ID and this user ID is considered to be ’non-switchable’ with regard to modifying the SAT logging setting (see the “SECOS - Security Control System - Audit” manual [1]).

  • Assigning the SAT-FILE-EVALUATION privilege (or a privilege set which includes this privilege) to a user ID causes the SAT function to be activated for this user ID. If SAT-FILE-EVALUATION is the only privilege for this user ID which initiates SAT logging, then SAT logging cannot be deactivated.

  • The SAT-FILE-MANAGEMENT privilege (or a privilege set which includes this privilege) cannot be assigned to the user ID TSOS.

Command return codes

(SC2)

SC1

Maincode

Meaning


0

CMD0001

Command executed without errors

2

0

SRM6001

Command executed with a warning


32

SRM6020

System error during command processing


64

SRM6040

Semantic error during command processing


130

SRM6030

Command cannot be processed at the present time