)CM
)CM
)CM ================================================================ */
)CM PROPRIETARY-STATEMENT:                                           */
)CM Licensed Material - Property of IBM                              */
)CM                                                                  */
)CM 5724-I63, 5724-H88, 5655-N01, 5733-W61                           */
)CM (C) Copyright IBM Corp. 1999, 2007                               */
)CM All Rights Reserved                                              */
)CM US Government Users Restricted Rights - Use, duplication or      */
)CM disclosure restricted by GSA ADP Schedule Contract with IBM Corp.*/
)CM ================================================================ */
)CM                                                                  */
)CM Change Activity:                                                 */
)CM                                                                  */
)CM F001143-35726 stelzerk: create admin agent templates using dmgr  */
)CM F001143-36770 stelzerk: update admin agent instructions          */
)CM 698264.1 2011407 vijaylax Document local_policy.jar migration    */
)CM                                                                  */ 
)CM ================================================================ */

)BLANK
)BLANK
------------------------------------------------------------------
Instructions for migrating a WebSphere Application Server for z/OS
administrative agent

)BLANK
If your back-level version of WebSphere Application Server is using 
the unrestricted jurisdiction policy files, you must perform the 
following special step to migrate these files to your new version of 
WebSphere Application Server. If you are not using the unrestricted 
jurisdiction policy files, you do not need to take the following step.

)BLANK
Before migrating, copy the modified local_policy.jar file to a 
temporary location.


)BLANK
The z/OS Migration Management Tool has created jobs based on the
information that you provided. These instructions tell you how to
modify the operating system and run the jobs to migrate WebSphere
Application Server for z/OS.

)BLANK
Guidelines:

)BLANK
    - If you created the target data sets (*.CNTL and *.DATA) on
      another (driving) system, you must copy them to the target
      system and give them the same data set names.

)BLANK
    - You must use these instructions on your target system.

)BLANK
Performing manual configuration updates
---------------------------------------

)BLANK
The z/OS Migration Management Tool for WebSphere Application Server
for z/OS does not attempt to update configuration data for your base
operating system or existing subsystems. You must take the following
manual steps before running the WebSphere Application Server for z/OS
migration jobs. Because you are migrating an existing system, some of
these steps might have already been taken during your previous
installation.

)BLANK
    -------------------------------------------------------------------

)BLANK
1.  Update your active BPXPRMxx member to have the following WebSphere
    Application Server for z/OS configuration file system:

)BLANK
    &MAHFS.

)BLANK
    mounted at:

)BLANK
    &MAMOUNTP.

)BLANK
    in read and write mode.

)BLANK
    For example:

)BLANK
       MOUNT FILESYSTEM('&MAHFS.')
       MOUNTPOINT('&MAMOUNTP.')
       TYPE(&AMFSTYPE.)
       MODE(RDWR)

)BLANK
    If you are configuring in a sysplex environment, you might want to
    add the NOAUTOMOVE parameter as follows:

)BLANK
       MOUNT FILESYSTEM('&MAHFS.')
       MOUNTPOINT('&MAMOUNTP.')
       TYPE(&AMFSTYPE.)
       MODE(RDWR) SYSNAME(<system_name>) NOAUTOMOVE

)BLANK
    The NOAUTOMOVE parameter in this example prevents the
    configuration file system from being mounted on a different z/OS
    system in a shared file system configuration, which could cause
    performance problems.  Replace <system_name> with the applicable
    system name for your installation.

)BLANK
    -------------------------------------------------------------------

)BLANK
2.  WebSphere Application Server for z/OS customization assumes that
    the following system data sets are in the system link list or link
    pack area:

)BLANK
    Language Environment     SCEERUN
                             SCEERUN2

)BLANK
    System SSL               SIEALNKE (z/OS 1.6 and above)

)BLANK
    Placing these data sets in the link list or link pack area improves
    performance and insulates your WebSphere Application Server for
    z/OS configuration from changes in data set names (for example,
    when migrating to z/OS 1.6).

)BLANK
    If the Language Environment or System SSL load module libraries are
    not in your system link list or link pack area, you must perform
    the following steps before starting any WebSphere Application
    Server for z/OS servers:

)BLANK
    - Make sure that the data sets are APF-authorized.

)BLANK
    - Complete the optional step below to add the data sets to STEPLIB
      in the server JCL and setupCmdLine.sh scripts.

)BLANK
    If you regenerate server cataloged procedures at any point, make
    sure that the data sets are added to the new cataloged procedures.

)BLANK
    -------------------------------------------------------------------

)BLANK
3.  Set up security system rules to run the Version 8.5 daemon and
    administrative agent controller under the same user IDs as used for
    your previous version.

)BLANK
    If you use RACF for your security system, use the following
    instructions.  If you use another SAF-compliant security system,
    contact the security system vendor for appropriate information.

)BLANK
    Check your MVS system log or use the TSO RLIST STARTED command to
    determine the user ID and group under which your previous daemon
    runs. (The previous default daemon user ID and group are WSDMNCR1
    and WSCFG1.)  Then, issue the following RACF command to create a
    correspoding STARTED profile for the Version 8.5 daemon cataloged
    procedure:

)BLANK
        RDEFINE STARTED &MADPN..*
                STDATA(USER(user) GROUP(group) TRACE(YES))
        SETROPTS RACLIST(STARTED) GENERIC(STARTED) REFRESH

)BLANK
    Check your MVS system log or use the TSO RLIST STARTED command
    to determine the user ID and group under which your previous
    administrative agent controller runs.  (The previous default
    administrative agent controller user ID and group are ASCR1 and
    WSCFG1.)  Then, issue the following RACF command to create a
    corresponding STARTED profile for the Version 8.5 deployment
    manager controller cataloged procedure:

)BLANK
        RDEFINE STARTED &MACPN..*
                STDATA(USER(user) GROUP(group) TRACE(YES))
        SETROPTS RACLIST(STARTED) GENERIC(STARTED) REFRESH

)BLANK
    Because the STARTED profile for the administrative agent servant
    is based only on the job name, no additional STARTED profile
    should be needed for the administrative agent servant, which has
    the same job name before and after migration.

)BLANK
    -------------------------------------------------------------------

)BLANK
4.  Add the security profile that was first required in Version 7.0.

)BLANK
    If the cell being migrated uses SAF authorization for EJB roles,
    create an EJBROLE profile for the auditor role (which was added 
    in Version 7.0).  Use the following RACF commands to create the 
    profile:

)BLANK
        RDEFINE EJBROLE (optionalSAFProfilePrefix.)auditor
                UACC(NONE)
        SETROPTS RACLIST(EJBROLE) REFRESH

)BLANK
    The auditor role should be granted to users who need to view and 
    modify the configuration settings for the security auditing 
    subsystem.  The administrator user ID created during 
    configuration should usually be granted this role:

)BLANK
        PERMIT (optionalSAFProfilePrefix.)auditor
               CLASS(EJBROLE)  ID(WSADMIN)  ACCESS(READ)
        SETROPTS RACLIST(EJBROLE) REFRESH

)BLANK
Running the migration jobs
--------------------------

)BLANK
The z/OS Migration Management Tool built a number of batch jobs with
the variables that you supplied. You must run the jobs in the order
listed below using user IDs with the appropriate authority.

)BLANK
Note: Whenever "file system update authority" is indicated, the user
      ID used to run the configuration job must have EITHER uid = 0
      OR the following UNIXPRIV class profile privileges:

)BLANK
        CONTROL access to SUPERUSER.FILESYS
        UPDATE  access to SUPERUSER.FILESYS.MOUNT
        READ    access to SUPERUSER.FILESYS.CHOWN
        READ    access to SUPERUSER.FILESYS.CHANGEPERMS
        READ    access to SUPERUSER.FILESYS.PFSCTL

)BLANK
      If the UNIXPRIV profile CHOWN.UNRESTRICTED is defined, then
      the SUPERUSER.FILESYS.CHOWN is not required.  For information
      about the UNIXPRIV class, see the z/OS Unix System Services
      Planning book.

)BLANK
Before you begin, complete the section above that is titled
"Performing manual configuration updates."

)BLANK
Follow the steps in the table below, which lists in order the jobs
that you must submit and the commands that you must enter. Special
handling notes are included in the table. All jobs are members of

)BLANK
&TRGCNTL.

)BLANK
Attention: After submitting each job, carefully check the output.
Errors might exist even when all return codes are zero.

)BLANK
Unless otherwise indicated, these jobs must be submitted by a user ID
that has authority to alter file permissions, change file ownership,
and change group membership of all files.  Please read the instructions
for each job carefully before submitting it.

)BLANK
)SEL &AMFSTYPE = HFS
+-----------+----------------------------------------------------------+
| BBOMAHFS  | User ID requirement:                                     |
+-----------+                                                          |
|           | The user ID that submits this job must have file         |
| Done:     | system update authority (see above) and the              |
|           | authority to allocate                                    |
|           |                                                          |
| By:       | &MAHFS.                                                  |
|           |                                                          |
|           | Before running this job, do the following:               |
|           |                                                          |
|           | Verify that the DD statement that defines the data set   |
|           | is valid for the storage rules defined on the target     |
|           | system.                                                  |
|           |                                                          |
|           | This job is not required if you already have a suitable  |
|           | mount point. If you are required to manually create the  |
|           | directory structure, this job performs the following     |
|           | tasks:                                                   |
|           |                                                          |
|           | o   Creates a mount point directory                      |
|           |                                                          |
|           |     &MAMOUNTP.                                           |
|           |                                                          |
|           | o   Allocates the configuration file system using        |
|           |     the hierarchical file system (HFS)                   |
|           |                                                          |
|           |     &MAHFS.                                              |
|           |                                                          |
|           | o   Mounts the file system at the mount point            |
|           |                                                          |
|           | Do not run this job if any of the following are true:    |
|           |                                                          |
|           | o   The configuration file system already exists and is  |
|           |     mounted at the desired mount point.                  |
|           |                                                          |
|           | o   The mount point directory is controlled by           |
|           |     automount.                                           |
|           |                                                          |
|           |     Either disable the automount rule for the            |
|           |     configuration mount point while running this         |
|           |     job, or perform the following steps manually:        |
|           |                                                          |
|           |      1. Allocate the configuration file system data set. |
|           |                                                          |
|           |      2. Issue the following shell command, which will    |
|           |         also cause automount to mount the file system:   |
|           |                                                          |
|           |         chmod 775 &MAMOUNTP.                             |
|           |                                                          |
|           | Before you begin:                                        |
|           |                                                          |
|           | The BBOMAHFS job assumes that your root file system is   |
|           | mounted in read and write mode. If it is not, manually   |
|           | create the directory                                     |
|           |                                                          |
|           | &MAMOUNTP.                                               |
|           |                                                          |
|           | For example:                                             |
|           |                                                          |
|           | If you plan to use /WebSphere/V8R5 as your directory,    |
|           | issue the following command from within the OMVS shell:  |
|           |                                                          |
|           | mkdir -p -m 775 /WebSphere/V8R5                          |
|           |                                                          |
|           | Attention:                                               |
|           |                                                          |
|           | The migration procedure will set the file ownership and  |
|           | permissions to match your previous configuration.        |
|           | Verify that the mount point directory is owned by your   |
|           | WebSphere Application Server administrator and that the  |
|           | group is assigned to the Administrators group. If it is  |
|           | not, then determine the user ID and group ID values that |
|           | are designated as owners of the previous WebSphere       |
|           | Application Server configuration. Either the numeric ID  |
|           | values or the user name and group name can be used.      |
|           | Issue the following command within the OMVS shell,       |
|           | replacing <user> and <group> with the user and group     |
|           | determined previously. Also replace <mountpoint> with    |
|           |                                                          |
|           | &MBMOUNTP.                                               |
|           |                                                          |
|           | chown <user>:<group> <mountpoint>                        |
|           |                                                          |
)ENDSEL
)SEL &AMFSTYPE = ZFS
+-----------+----------------------------------------------------------+
| BBOMAZFS  | User ID requirement:                                     |
+-----------+                                                          |
|           | The user ID that submits this job must have file         |
| Done:     | system update authority (see above) and the              |
|           | authority to allocate                                    |
|           |                                                          |
| By:       | &MAHFS.                                                  |
|           |                                                          |
|           | Before running this job, do the following:               |
|           |                                                          |
|           | Verify that the DD statement that defines the data set   |
|           | is valid for the storage rules defined on the target     |
|           | system.                                                  |
|           |                                                          |
|           | This job is not required if you already have a suitable  |
|           | mount point. If you are required to manually create the  |
|           | directory structure, this job performs the following     |
|           | tasks:                                                   |
|           |                                                          |
|           | o   Creates a mount point directory                      |
|           |                                                          |
|           |     &MAMOUNTP.                                           |
|           |                                                          |
|           | o   Allocates the configuration file system using the    |
|           |     z/OS Distributed File Service zSeries File System    |
|           |     (zFS)                                                |
|           |                                                          |
|           |     &MAHFS.                                              |
|           |                                                          |
|           | o   Mounts the file system at the mount point            |
|           |                                                          |
|           | Do not run this job if any of the following are true:    |
|           |                                                          |
|           | o   The configuration file system already exists and is  |
|           |     mounted at the desired mountpoint.                   |
|           |                                                          |
|           | o   The mount point directory is controlled by           |
|           |     automount.                                           |
|           |                                                          |
|           |     Either disable the automount rule for the            |
|           |     configuration mount point while running this         |
|           |     job, or perform the following steps manually:        |
|           |                                                          |
|           |     1. Allocate the configuration file system data set.  |
|           |                                                          |
|           |     2. Issue the following shell commands, which will    |
|           |        also cause automount to mount the file system     |
|           |                                                          |
|           |        chmod 775 &MAMOUNTP.                              |
|           |                                                          |
|           | Before you begin:                                        |
|           |                                                          |
|           | The BBOMAZFS job assumes that your root file system is   |
|           | mounted in read and write mode.  If the root file system |
|           | is not mounted in read and write mode, manually          |
|           | create the directory                                     |
|           |                                                          |
|           | &MAMOUNTP.                                               |
|           |                                                          |
|           | For example:                                             |
|           |                                                          |
|           | If you plan to use /WebSphere/V8R5 as your directory,    |
|           | issue the following command from within the OMVS shell:  |
|           |                                                          |
|           | mkdir -p -m 775 /WebSphere/V8R5                          |
|           |                                                          |
|           | Attention:                                               |
|           |                                                          |
|           | The migration procedure will set the file ownership and  |
|           | permissions to match your previous configuration.        |
|           | Verify that the mount point directory is owned by your   |
|           | WebSphere Application Server administrator and that the  |
|           | group is assigned to the Administrators group. If it is  |
|           | not, then determine the user ID and group ID values that |
|           | are designated as owners of the previous WebSphere       |
|           | Application Server configuration. Either the numeric ID  |
|           | values or the user name and group name can be used.      |
|           | Issue the following command within the OMVS shell,       |
|           | replacing <user> and <group> with the user and group     |
|           | determined previously. Also replace <mountpoint> with    |
|           |                                                          |
|           | &MBMOUNTP.                                               |
|           |                                                          |
|           | chown <user>:<group> <mountpoint>                        |
|           |                                                          |
)ENDSEL
+-----------+----------------------------------------------------------+
| BBOMACP   |                                                          |
+-----------+                                                          |
|           | &MBPROCL.                                                |
| Done:     |                                                          |
|           | Attention:                                               |
|           |                                                          |
| By:       | WebSphere Application Server Version 8.5 requires the    |
|           | new STARTED procedures that you provided when you        |
|           | created your migration definition.  Depending on what    |
|           | these are, you might be required to create additional    |
|           | RACF STARTED profiles.                                   |
|           |                                                          |
|           | It is recommended that you use the same user ID and group|
|           | memberships that you used in your previous version.      |
|           |                                                          |
|           | This job copies the tailored start procedures,           |
|           | parameters, and EXECs to the runtime libraries.          |
|           |                                                          |
|           | Attention:                                               |
|           |                                                          |
|           | Be aware that you might overlay existing members in      |
|           | the above data set.                                      |
|           |                                                          |
+-----------+----------------------------------------------------------|
| Select    | The job or jobs in this step must be submitted from a    |
|===========| WebSphere Application Server administrator's user ID.    |
|           | Select whether to use the single or multi job option.    |
| Option 1  |                                                          |
| --------- | Submit the job, and verify that the return code is 0.    |
| BBOWMG3A  | If using the multi-job option verify the return code is  |
|-----------| 0 before submitting the next job.                        |
|           |                                                          |
| Option 2  | This step performs the main migration procedure. Based   |
| --------  | on the information that you provided when you created    |
| BBOWAPRO  | your migration definition and your existing              |
| BBOWAPRE  | configuration, your previous server will be migrated     |
| BBOWAPOS  | to Version 8.5.                                          |
+===========+ The migration steps include:                             |
|           |   1) creating a target profile in the new release.       |
| Done:     |   2) creating a backup of the source profile.            |
|           |   3) migrating the backup profile into the new profile.  |
|           | All three steps can be done using a single job:          |
| By:       |                BBOWMG3A                                  |
|           | OR they can be individually submitted in this order:     |
|           |      BBOWAPRO, BBOWAPRE, BBOWAPOS                        |
+-----------+----------------------------------------------------------+
| --------  | All WebSphere Application Server processes require       |
+-----------+ access to the Language Environment and System SSL load   |
|           | modules.                                                 |
| Done:     |                                                          |
|           | If the SCEERUN, SCEERUN2, and System SSL load module     |
|           | libraries are not in the system link list or link pack   |
| By:       | area, add them to the STEPLIB DD concatenation in each   |
|           | of the following cataloged procedures in                 |
|           |                                                          |
|           | &MBPROCL.:                                               |
|           |                                                          |
|           |     &MACPN                                               |
|           |     &MASPN                                               |
|           |     &MADPN                                               |
|           |                                                          |
|           | and also add the full data set names, separated by       |
|           | colons (:), to the STEPLIB variable in the shell script: |
|           |                                                          |
|           |     &MAMOUNTP./                                          |
|           |     &MADIRN./                                            |
|           |     profiles/default/bin/setupCmdLine.sh                 |
|           |                                                          |
|           | When modifying the setupCmdLine.sh script, do not        |
|           | remove lines or comment them out, as this might cause    |
|           | problems with automated updates to the script.           |
|           |                                                          |
|           | Add only those data sets that are NOT in the link list   |
|           | or link pack area.                                       |
|           |                                                          |
+-----------+----------------------------------------------------------+
| Done:     | Copy unrestricted jurisdiction policy files              |
|           |                                                          |
|           | If you saved a copy of local_policy.jar in the           |
|           | beginning of the migration process take the following    |
| By:       | steps:                                                   |
|           | 1)After migration completes successfully, mount the new  |
|           | product hfs read/write.                                  |
|           | 2)Copy the modified local_policy.jar from the temporary  |
|           | location to the following directory on the new WebSphere |
|           | Application Server installation:                         |
|           | WAS_HOME/java/lib/security                               |
|           | 3)Mount the new product HFS as read/only                 | 
|           |                                                          |
|           |                                                          |
+----------------------------------------------------------------------+
|           | Migrate Managed Base Nodes                               |
| Done:     |                                                          |
|           | Before starting the Version 8.5 administrative agent,    |
|			| migrate all registered base nodes.					   |
|			|  														   |
|           | The Version 8.5 administrative agent will only be        |
| By:       | used after all registered application servers have       | 
|           | been migrated.                                           |
|			| 														   |
|			| Follow the managed base node migration instructions      |
|			|														   |
|           | Note: If the managed base node is also registered to a   |
|           | job manager, the managed base node must be unregistered  |
|           | from the job manager before managed base node migration. | 
+-----------+----------------------------------------------------------+
|           | Shut down the application servers and daemon.            |
| Done:     |                                                          |
|           | If there are registered or unregistered application      |
|           | servers on the same LPAR as the administrative agent,    | 
|           | the servers must be shutdown.	                           |
|			|  														   |
|			| The daemon is required to run at the Version 8.5 level   |
|           | of code for all the servers that it manages on the same  |
| By:       | administrative agent LPAR. It will be at the Version 8.5 |
|           | level when the administrative agent is started.          |
|           |                                                          |
+-----------+----------------------------------------------------------+
|           | Start the Version 8.5 administrative agent.              |
| Done:     |                                                          |
|           | After migrating all registered application servers,      |
|           | the previous administrative agent should be shutdown.    |
| By:       |                                                          |
|           | Use the existing commands that you currently use         |
|           | to start your previous server, but replace the STARTED   |
|           | procedure name with the value that you entered when you  |
|           | created your migration definition.                       |
|           |                                                          |
|           | &MACPN.                                                  |
|           |                                                          |
|           | This command starts the administrative agent. Wait until |
|           | the server has finished initializing before proceeding.  |
|           |                                                          |
|           | The following message appears on the console and in the  |
|           | job log of BBOADMA:                                      |
|           |                                                          |
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |
|           |   z/OS CONTROL PROCESS BBOADMA                           |
|           |                                                          |
+-----------+----------------------------------------------------------+
| Done:     | Register managed base nodes                              |
|           |                                                          |
|           | The managed base nodes are un-registered from the        |
|           | previous administrative agent during managed base node   |
| By:       | migration and must be registered to the Version 8.5      |
|           | administrative agent.                                    |
|           |                                                          |
|           | After all previously registered base nodes have been     |
|           | migrated to Version 8.5 and the Version 8.5              |
|           | administrative agent has been started, register the      | 
|           | Version 8.5 base node to the Version 8.5 administrative  |
|           | agent.                                                   |
|           |                                                          |
|           | Note: You will need to also register the base            |
|           | node to any job manager that it was registered to before |
|           | migration and recreate the jobs.                         |
+----------------------------------------------------------------------+
|                                                                      |
| Migration has now been completed.                                    |
|                                                                      |
+----------------------------------------------------------------------+





