Z-TAP Pre-Installation

This section contains information that you should review before you install or update the Guardium for Mainframes Z-TAP component.

 

 

Verifying the Product Package

Verify that you have the following items:

If any of these items are missing, please contact Guardium Technical Support.

 

Roles and Assignments for Z-TAP Installation and Configuration

Depending on the size and distribution of your system, several people might contribute to the Z-TAP installation and configuration process. Use the information in the table below to help plan the installation process. If more than one person will participate in the installation, consider meeting with all participants in advance to communicate the product requirements.

In addition, the Z-TAP started task must be granted appropriate security authorizations before the product can be run successfully. For more information about security requirements, see the Security Requirements section of this guide.

Roles and Tasks for Installation Process

Role

Tasks Performed

Specific Skills or Knowledge Required

System Programmer

  • APF-authorize the library that contains the Z-TAP load modules.

  • Copy the Z-TAP libraries from the distribution media to z/OS.

  • Setup the required product license on the z/OS mainframe.

  • Set initial product parameters with input from the DB2 database administrator.

  • Together with the Network Administrator, set the host name and port for the Z2000 appliance server.

  • Ability and authority to APF-authorize data sets.

  • Ability to make the APF authorization permanent, so that it will persist after system IPL.

  • Knowledge of site-specific data set name requirements, if any.

Security Administrator

Provide appropriate authorities and privileges in the security software for Z-TAP.

Knowledge of RACF or equivalent security system.

Network Administrator

Authorize TCP/IP connections, as required. Provide the TCPIP.DATA data set name, and TCP/IP port numbers to the system programmer for use during initial product configuration.

  • Knowledge of site-specific port numbering standards, if any.

  • Knowledge of the local TCP/IP configuration.

DB2 System Administrator or DBA

Provide appropriate authority for the Z-TAP started task to access the DB2 catalog on z/OS.

Knowledge of DB2 security requirements.

Guardium for Mainframes administrator

Perform license administration on the Z2000 appliance and create initial Guardium user profiles.

Knowledge of Guardium’s administration.

 

Mainframe Software Requirements

Before unloading and installing Z-TAP, verify that you have the following software installed on your z/OS system:

 

Required Software



IBM z/OS version 1.6 or later (64-bit mode required)



DB2 for z/OS version 7 or 8



IBM TCP/IP version 3.1 or later

 

Security Requirements

For Z-TAP to run successfully, you must provide the product with adequate access to operating system and database resources. By using a security administration product (such as RACF), you can establish application profiles for Z-TAP started tasks.

DB2 Security Considerations

Verify or change the following DB2 settings:

RACF Security Considerations

Verify or change the following RACF settings:

APF Authorization

The library that contains the Z-TAP load modules (?guardiumhlq.LOAD) must have Application Program Facility (APF) authorization.

Z-TAP uses dataspaces, cross-memory services, and other functions that require APF authorization. These are common and necessary requirements of system-level software.

To APF-authorize the load library, your system programmer will issue an APF command similar to the following examples:

SETPROG APF,ADD,DSNAME=?guardiumhlq.LOAD,SMS

SETPROG APF,ADD,DSNAME=?guardiumhlq.LOAD,VOLUME=volume

 

Optimizing Performance

Z-TAP will run faster and more reliably if the following configuration settings are made:

 

Supported Attach Facilities

Z-TAP supports the following local attach facilities for DB2 on z/OS:

Z-TAP supports the following facilities for distributed connections:

 

Information Needed for Installation

Guardium for Mainframes is an enterprise product that comprises components that run on the z/OS source DBMS platform (Z-TAP) and components that run on a network based appliance (Z2000). Administrator and user tasks are done using the Guardium interface, which runs in your web browser. For Z-TAP to communicate with the Z2000 appliance, you must have TCP/IP network connections between the LPAR where auditing is performed and the appliance.

Before installing Z-TAP, you will need to know the IP port numbers that will be used by the product. Your network administrator may need to establish these for you.

 

Preparing for Disaster Recovery

Guardium for Mainframes is an important piece of your database security strategy and to ensure business process continuity, you will want to recover Z-TAP at the same time you recover your z/OS hosted databases. To fully recover Z-TAP, you must include the following resources in your disaster recovery plan:

Resource

Description

?guardiumhlq.ADMIN

This library contains the product keys for all licensed installed NEON products.

?guardiumhlq.CNTL

This library contains the control members for the product, including sample JCL.

?guardiumhlq.DBRMLIB

This library contains the DB2 definitions for Z-TAP.

?guardiumhlq.EXEC

This library contains the REXX executables needed to configure the product.

?guardiumhlq.LOAD

This library contains the executable load modules needed to execute the product.

?guardiumhlq.MESSAGES

This library contains descriptions for product messages.

?guardiumhlq.MLIB

This library contains messages issued by the ISPF interface.

?guardiumhlq.MSG

This library contains the message modules used by the product.

?guardiumhlq.PLIB

This library contains ISPF panels used by the product.

 

Allocating the ADMIN Library

The Z-TAP component uses an administration (ADMIN) library to manage and maintain product keys and the associated product load libraries. You must allocate and catalog this administration library. Use the following steps to allocate the library:

1. Locate the ALLOCATE sample JCL in the ?guardiumhlq.CNTL data set.

2. Edit the JCL to include a valid job card and meet your site requirements.

3. Submit the job to allocate the library. The job allocates a data set with the format shown in the following table.

Role Allocation Requirements for the ADMIN library

Item

Value

Data set format

Partitioned data set (PDS)

Record format

Fixed block (FB), 80-character logical records

Allocated space

Two tracks and 10 directory blocks