z/OSMF setup (for system programmers)¶
The z/OS side of the extension talks only to z/OSMF REST services. It installs nothing on z/OS. This page lists what has to be in place, and how to check it.
Audience
This page is for the z/OS system programmer and security administrator. Developers can send them the link.
Services used¶
| Feature in the extension | z/OSMF service | URL prefix |
|---|---|---|
| Data sets, members, copy, rename, search, download | z/OS data set and file REST interface | /zosmf/restfiles/ds |
| USS files | z/OS data set and file REST interface | /zosmf/restfiles/fs |
| Jobs, spool, submit, cancel, purge, job JCL | z/OS jobs REST interface | /zosmf/restjobs/jobs |
| TSO commands | TSO/E address space services | /zosmf/tsoApp/tso |
| MVS console commands | z/OS console services | /zosmf/restconsoles/consoles |
| Connection test | z/OSMF information | /zosmf/info |
Every request uses HTTPS with Basic authentication (user ID and password or passphrase) and the header X-CSRF-ZOSMF-HEADER: true. No browser is involved, so CORS settings don't matter.
Checklist¶
z/OSMF server¶
- The z/OSMF started tasks are running (by default the angel
IZUANG1and the serverIZUSVR1). The server is ready when messageCWWKF0011Iappears. - Note the HTTPS port (message
IZUG349Iin the log; often 443 or 10443). Developers enter it in the connection wizard. - The server certificate is trusted by the developers' PCs, or developers choose Accept self-signed certificate. A certificate signed by your internal CA is better.
Users¶
- Each developer's user ID is connected to the z/OSMF user group (default
IZUUSER), created by the IBM-supplied security setup jobs (IZUSEC / IZUAUTH, depending on the release). - Each developer has an OMVS segment (for USS access) and a TSO segment (for TSO commands).
Data set and file REST interface¶
- The CEA started task is running and has the TRUSTED attribute (RACF).
-
COMMON_TSOis configured inIZUPRMxx, and the z/OSMF user group is authorized to its logon procedure and account number. - The logon procedure region is large enough (at least 65536 KB is commonly recommended).
-
IPCMSGQBYTESinBPXPRMxxis at least 20971520.
Jobs REST interface¶
- Developers can submit jobs, and are allowed to view and purge their own jobs through JESSPOOL / JESJOBS rules. To see other users' jobs (job filter owner
*), they need the matchingJESSPOOLaccess.
TSO/E address space services¶
- The account number and logon procedure developers use are valid for them. In the extension these are the settings
mainframe.zos.tsoAccount(defaultACCT#) andmainframe.zos.tsoProc(defaultIKJACCNT). Tell developers the right values.
Console services¶
- The
OPERCMDclass is active and MVS commands are protected (MVS.**). - Developers who may use console commands have access to
MVS.MCSOPER.<userid>and to the commands they need, for exampleMVS.DISPLAY.**for display commands only.
Verify from a browser¶
Log in with a developer's user ID:
| URL | Expected |
|---|---|
https://<host>:<port>/zosmf/info |
JSON with zosmf_version |
https://<host>:<port>/zosmf/restjobs/jobs?owner=<USERID> |
JSON list of the user's jobs |
https://<host>:<port>/zosmf/restfiles/ds?dslevel=<USERID>.* |
JSON list of data sets |
Verify from the extension¶
| Action | Expected result |
|---|---|
| Test Connection | Connected to z/OS … (z/OSMF …) |
| Expand Data Sets | The user's data sets |
Issue TSO Command TIME |
The current time |
Issue MVS Console Command D T |
IEE136I LOCAL: TIME=… |
Typical errors¶
| Error in the extension | Usual cause |
|---|---|
401 |
Wrong password, revoked user, or the user isn't in the z/OSMF user group |
403 on one service only |
The user lacks authority for that service (TSO, console, JES) |
| TSO command hangs or returns nothing | Wrong account or logon procedure, or CEA / COMMON_TSO not set up |
Console command returns IEE345I … AUTHORITY INVALID |
Missing OPERCMD access |
self signed certificate |
Certificate not trusted; use an internal-CA certificate, or have developers accept it |
For the exact RACF statements, see IBM's z/OSMF Configuration Guide for your z/OS release, and the Zowe documentation on configuring z/OSMF security. The same z/OSMF setup serves Zowe and this extension.