<!-- ================================================================ -->
<!-- PROPRIETARY-STATEMENT:                                           -->
<!-- Licensed Material - Property of IBM                              -->
<!--                                                                  -->
<!-- 5724-I63, 5724-H88, 5655-N01, 5733-W61                           -->
<!-- (C) Copyright IBM Corp. 1999, 2012                               -->
<!-- All Rights Reserved                                              -->
<!-- US Government Users Restricted Rights - Use, duplication or      -->
<!-- disclosure restricted by GSA ADP Schedule Contract with IBM Corp.-->
<!-- ================================================================ -->
<!--                                                                  -->
<!-- Change Activity:                                                 -->
<!--                                                                  -->
<!--   WS14568 H28W500 021118  PDML: Initial release.                 -->
<!--   MD15332 H28W500 030108  PDML: Moved "Run install scripts"      -->
<!--                                 section to before BBOWIAPP       -->
<!--   MD15360 H28W500 030108  PDML: Add Step to create JCLLIB        -->
<!--   MD15361 H28W500 030108  PDML: Updated cluster start section    -->
<!--   MD15362 H28W500 030108  PDML: Updated BBOWCPY1                 -->
<!--   MD15395 H28W500 030110  PDML: add BBOWCPY2                     -->
<!--   MD15430 H28W500 030117  PDML: add SBBOLPA note                 -->
<!--   WS14568.02 H28W500 030205 PDML: add a step to start the daemon -->
<!--                                 remove the BBOWJCLL step         -->
<!--                                 change WLM setup.                -->
<!--                                 add BBOMCFG2 step.               -->
<!--   MD15432 H28W500 030210  PDML: remove JCLLIBDS                  -->
<!--  MD15808 H28W500 030212  PDML: change &WSNODE to &SYSNAME        -->
<!--   MD14568 H28W500 021303  PDEJ: Integral JMS Provider            -->
<!--   MD15326 H28W500 030214  PDML: add warning to BBOWCPY1.         -->
<!--   MD15863 H28W500 030215  PDG1: WLM ... &&SYSNAME and warning.   -->
<!--   MD15867 H28W500 030215  PDML: change daemon start parameter.   -->
<!--   MD16284 H28W500 030319  PDML: update ENV=.... for WLM.         -->
<!--   MD16200 H28W500 030319  PDML: add bbow5sh.                     -->
<!--   MD16282 H28W500 030321  PDML: need read access to SYS1.TCPPARMS-->
<!--                                 and SYS1.PARMLIB.                -->
<!--   MD16543 H28W500 030331  PDML: correct start syntax for server. -->
<!--   MD16690 H28W500 030409  PDML: updated user requirement for jobs-->
<!--   MD16557 H28W500 030415  PDML: update samples.                  -->
<!--   MD17229 H28W500 030602  PDGK: add BBOCR2FA.                    -->
<!--   PQ75314 H28W500 030616  PDML: change user ID requirement for   -->
<!--                                 BBOMCFGU from WSADMIN to UID=0.  -->
<!--   MD17286 H28W500 030620  PDG1: Adjust ownership                 -->
<!--   PQ75181 H28W500 030709  PDML: correct TCP/IP port infomation.  -->
<!--   PQ74952 H28W500 030618  PDSS: Updates for ID defects MD16833,  -->
<!--                                 MD17105,MD17106,MD17107,PQ74952  -->
<!-- MD15508.2 H28W500 030721  PDML: Move BBOMCFG2 after BBOCR2FA.    -->
<!--   PQ75949 H28W500 030806  PDGK: Change BBOCR2FA instructions.    -->
<!--   MD17896 H28W500 030829  PDML: fix max length problem for SCELIB-->
<!--                                 and BBOLPA.                      -->
<!--   WS15621 H28W502 030825  PDRZ: Modify oper command instructions -->
<!--   WS17709 H28W502 030930  PDGK: RACF Keyring changes             -->
<!--   MD18220 H28W502 031013  PDSS: fixed confusing wording in step 8-->
<!--   PQ78664 H28W502 031024  PDSS: Added new prelim PARMLIB step    -->
<!--   PQ80596 H28W500 031117  PDSS: moved step for setting MQ file   -->
<!--                                 authorization bits from bbojjins.-->
<!--   MD18797 H28W502 031204  PDSS: Fixed &PARMLIB. overflow problem -->
<!--   PQ81471 H28W502 031205  PDML: change userid requirement for    -->
<!--                                 BBOWIVT.                         -->
<!--   PQ81402 H28W502 040107  PDML: add SGSKLOAD.                    -->
<!--   MD19168 H28W510 020204  PDML: add SCEERUN2.                    -->
<!--   MD19242 H28W510 021004  PDML: change some sample text.         -->
<!--   MD19809 H28W510 040904  PDML: remove BBOMCFGU.                 -->
<!--   LIDB2117-39.1 H28W510 040610  PDML: Removed reference to IJP   -->
<!--   238129  H28W600 100804  PDML: update instructions for V6.      -->
<!--   LIDB2461-26 H28W510 111604 DB: Added instructions for BBOCRTTS -->
<!--                                  BBOCRTSC, BBODRPTS, BBODRPSC    -->
<!--   244703  H28W600 111904  PDML: update instructions for V6.      -->
<!--   244860  H28W600 120204    DB: Add TCPIP instructions for SI    -->
<!--                                 ports                            -->
<!--   245688  H28W600 120704    DB: Remove CSQMPEH                   -->
<!--   246698  H28W600 120804    DB: improve spacing in scheduler DB  -->
<!--                                 configuration section            -->
<!--   246983  H28W600 121604    DB: Revise instructions based on     -->
<!--                                 new dataset panels               -->
<!--   249091  H28W601 011005    DB: Updates based on review comments -->
<!--   247922  H28W601 011905    DB: BBOCBRAK instruction update      -->
<!--   251673  H28W601 012605    DB: More updates on review comments  -->
<!--   253598  H28W601 020705    DB: Remove blank line                -->
<!--   253951  H28W601 021705    DB: add BBOWCFGW to instructions     -->
<!--   257024  H28W602 022205    DB: add some missing periods and fix -->
<!--                                 max length problem               -->
<!--   241041  H28W601 032205  PDSS: Added instructions for when      -->
<!--                                 BBOWWPFA fails on second try     -->
<!--   259928  H28W602 041405    DB: Only  generate BBORTSS5 section  -->
<!--                                 if answer for in STEPLIB is Y    -->
<!--   262097  H28W602 041505    DB: update instructions based on RRS -->
<!--                                 removal from dialog              -->
<!--   253275  H28W602 041505    DB: Remove CTRACE instructions       -->
<!--   271696  H28W602 042805    DB: Add text for BBOWCFGW            -->
<!--   262089  H28W602 042805    DB: remove WLM static instructions   -->
<!--   274807  H28W602 051105    DB: BBOWCFGW should be run as admin  -->
<!--   275945  H28W602 051305    DB: remove stray reference to RRS    -->
<!--   279429  H28W602 052705  PDML: add directory verifications step.-->
<!--   281074  H28W602 060305  PDML: display the dir verfication step -->
<!--                                 only if USERHOME is not tmp.     -->
<!-- LIDB2356-34 H28W602 052705 PDML: add SIP port.                   -->
<!--   283304  H28W602 061305  PDML: remove dir verification step.    -->
<!--  PK07374  H28W602 062105  PDML: add directory verifications step.-->
<!--   290470  H28W602 071805  PDML: remove BBOSGSK and SYSEXEC.      -->
<!-- LIDB3561-19 H28W610 082505  PDML: IHS update.                    -->
<!-- LIDB2634  H28W610 083005  PDML: security out of box update.      -->
<!--   302474  H28W610 090105  PDML: update instructions for security.-->
<!--   306104  H28W610 091805    DB: add admin console ports to       -->
<!--                                 TCPIP section                    -->
<!--   306432  H28W610 091905    DB: reword and reorder port listing  -->
<!--   311865  H28W610 100805    DB: remove SCEERUN items             -->
<!--   313366  H28W610 101405  PDML: move text around ERRLOG.         -->
<!--   317828  H28W610 111205  PDML: add OMVS WLM setup instructions. -->
<!--   322399  H28W610 111605    DB: remove webserver jobs            -->
<!--   325782  H28W610 112105    DB: change BBORTSS5 to BBORTS61      -->
<!--   328482  H28W610 120105    DB: add name of infocenter article   -->
<!--   329630  H28W610 120705    DB: remove references to XA logstream-->
<!--   329934  H28W610 121305    DB: remove parmlib from BBOWCPY1     -->
<!--   330776  H28W610 121405    DB: update instructions based on     -->
<!--                                 change to SBBOLPA/SBBOLOAD       -->
<!--   337027  H28W610 011206    DB: remove SEL stmt for BBOWCPY1     -->
<!--   337853  H28W610 011206    DB: fix some typos                   -->
<!--   333384  H28W610 011306    DB: add zfs support                  -->
<!--  333384.1 H28W610 011906    DB: filesystem should be two words   -->
<!-- 338772.11 H28W610 012006    DB: remove scheduler DB jobs         -->
<!--  337515   H28W610 012306    DB: updates for STEPLIB changes      -->
<!--  330804   H28W610 012406    DB: add automount warning            -->
<!--  342400   H28W610 013006    DB: change FILEZFS to FSTYPE         -->
<!--  338949   H28W610 013006    DB: update SMF instructions          -->
<!--  342461   H28W610 013106    DB: update OPERCMDs instructions     -->
<!--  338132   H28W610 020606  PDML: add SBBGLOAD.                    -->
<!--  341403   H28W610 020906  PDML: add a note for BBOSBRAM          -->
<!--  354688   H28W610 031406    DB: LE/SSL datasets dont go into LPA -->
<!--  356728   H28W610 032406    DB: use ASFSTYPE                     -->
<!-- PK20049   H28W610 042206    DB: instructions for LE STEPLIB      -->
<!--  364931   H28W610 042406    DB: updates for non root install     -->
<!--  373993   H28W610 082206    DB: SAF profile update for zFS       -->
<!--  370154   H28W610 083106    DB: add verify stmt for HFS job      -->
<!--  390937   H28W610 100206    DB: 64-bit instruction updates       -->
<!--  348320   H28W610 102506    DB: updates for asterisk id          -->
<!--  400982   H28W610 102606    DB: Add text for AUTOMOVE            -->
<!--  402402   H28W610 110106    DB: Reword text for AUTOMOVE         -->
<!--  411108   H28W610 121206    DB: Fix possible length error        -->
<!--  412596   H28W610 010307    DB: Add SBBGLOAD references          -->
<!--  412597   H28W610 010807    DB: fix minor text issues            -->
<!-- LIDB4489-16 H28W700 040107  DB: 64-bit updates                   -->
<!--  425357   H28W610 040907    DB: use aggrgrow option for ZFS      -->
<!--  447303   V7.0    070614  PDOP: Userid simplification            -->
<!--  447258   V7.0  20070626  PXTN: Convert zmpt variables.          -->
<!-- LIDB4194-52 V7.0  070907  PDOP: Flexible management              -->
<!--LIDB4302-11.10 V7.0    070824    DB: Rename file system job       -->
<!--  465452   V7.0    101907  PDOP: Updated profile cleanup info     -->
<!--  LIDB4689  V7.0    20071024 DMB: Move load modules to hfs        -->
<!--  466649   V7.0    102507  PDOP: Remove refs to config dialog     -->
<!--  484621   V7.0    112807  PDOP: Updated "Z" proclib references   -->
<!--  489808   V7.0    122007   PXT: Change order of BBOWCPY1 to run  -->
<!--  492063   V7.0    011507   DMB: Use one step RACF jobs           -->
<!--  502633   V7.0    030308  PDOP: Removed use of "InfoCenter"      -->
<!--  504724   V7.0    031508  PDOP: Added prod file system directions-->
<!--  500745   V7.0    20080407 PXT: Rename from BBOCBRAJ to BBOCBRAK -->
<!--511429.1 V7.0   20080519   DMB: Create SR id in bbosbrac          -->
<!--  538461   V7.0   20080723 PDOP: Add SCLBDLL2 to system link list -->
<!--  540011   V7.0   20080724 DMB: Add adjunct id                    -->
<!--  546577   V7.0   20080829 PDOP: Add daemon id                    -->
<!--  567032   V7.0   20081203 PDOP: Clean up                         -->
<!--  PK70886  V7.0   20081216  DMB: Add region size warning info     -->
<!--  567032.1 V7.0   20090116 PDOP: Additional clean up              -->
<!-- PK83899   V7.0   20090413 DMB: Update section on SCHEDxx member  -->
<!-- F908-13390.2 V8.0 200907xx DMB: BPXPRMxx updates for noautomove  -->
<!-- PK94663  V7.0     20090922  DMB: Update BBOMSGC step             -->
<!-- PM12309  V7.0    20100721 DMB: Updates for REUSASID              -->
<!-- F908-32216 V8.0  20100727 PDOP: Replace BBOWCPY1 with BBOWPROC   -->
<!-- 680815     V8.0  20101201 PDOP: Added step to verify SDK         -->
<!-- 688594     V8.0  20110130 PDOP: Change "v7" to "v8"              -->
<!--  715560   V8.0   20110908 PDOP: Show WAS version                 -->
<!-- F43152-51709.2 V8.5 20111013 PDOP: V8.5 release basics           -->
<!-- F43152-56172   V8.5 20111228 PDOP: Add VE ports                  -->
<!-- 725442         V8.5 20120106 PDOP: Updated SDK selection         -->
<!-- 730602         V8.5 20120309 PDOP: Remove admin asynch references-->
<!-- 739067       V8.5.5 20121206 PDOP: TMPDIR support                -->
<!-- 745081       V7.0   20130306 PDOP: Update SAF profile privileges -->
<!-- 747114       V8.5.5 20130413 PDOP: Skip BBOWIVT if no IVT app    -->
<!-- 756277       V8.5.5 20140221 PDDH: Add Java 7.1 to cust. instr.  -->
<!-- ================================================================ -->

-----------------------------------------------
WebSphere Application Server for z/OS V8.5 customization instructions:

Application server ${zServerShortName}  (cell ${zCellShortName}, node ${zNodeShortName})
Tailored on ${ZDATE} at ${ZTIMEL} by ${ZUSER}
WCT version ${wctVersion} build ${wctBuild}

The customization tools have created jobs based on the information you
provided. These instructions tell you how to modify the operating
system and run the jobs to customize WebSphere for z/OS.

RULES:

1.  If you created the target data sets (*.CNTL and *.DATA) on another
    (driving) system, you must copy them to the target system and give
    them the same data set names.

2.  You must perform these instructions on your target system.

Doing manual configuration updates

----------------------------------

You must perform the following manual steps on the target z/OS system
before running the WebSphere for z/OS configuration jobs.

1.  Update BLSCUSER. Refer to member BBOIPCSP in

    ${zTargetHLQ}.CNTL

    In order to use the IPCS support provided by the product, append
    the contents of this member to the BLSCUSER member in your IPCSPARM
    or system PARMLIB datasets.

    -------------------------------------------------------------------

2.  Update SCHEDxx. Refer to member BBOSCHED in

    ${zTargetHLQ}.CNTL

    In order to set the correct program properties for the WebSphere
    for z/OS run-time executables, append the contents of this member
    to the SCHEDxx member in your system PARMLIB concatenation.

    Note: When you are finished, issue the command SET SCH=xx to
    activate SCHEDxx and load a new program properties table.  This
    action does not need to be performed if the target z/OS system is
    at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED
    member contains already exists in the IBM-supplied PPT table at
    those z/OS levels.

    -------------------------------------------------------------------

3.  If you want to collect the SMF120 records created by the run-time
    servers, update SMFPRMxx via the following:

    EXAMPLE:

       SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),
                          TYPE(0,30,70:79,88,89,120,245))
                                                ---

    For details on the SMF records, see related topics in the
    WebSphere for z/OS Information Center at
    http://www.ibm.com/software/webservers/appserv/zos_os390/library/

    -------------------------------------------------------------------

<!-- import documents/cntl/productFileSystem.txt -->

    -------------------------------------------------------------------

5.  Update your active BPXPRMxx member to have the following WebSphere
    for z/OS configuration file system:

    ${zConfigHfsName}

    mounted at:

    ${zConfigMountPoint}

    in read/write mode.

    EXAMPLE:

<!-- if (${zFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')
         MOUNTPOINT('${zConfigMountPoint}')
          TYPE(${zFilesystemType})
          MODE(RDWR) PARM('AGGRGROW') NOAUTOMOVE
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')
         MOUNTPOINT('${zConfigMountPoint}')
          TYPE(${zFilesystemType})
          MODE(RDWR) NOAUTOMOVE
<!-- endif -->

    The NOAUTOMOVE parameter in the example above prevents the
    configuration file system from being mounted on a different z/OS
    system in a shared file system configuration, which could cause
    performance problems.

<!-- if (${zFilesystemType} == ZFS) -->
    If you have specified "aggrgrow=on" in your IOEFSPRM parmlib member,
    you can omit the AGGRGROW parm shown in the above examples
<!-- endif -->

    -------------------------------------------------------------------

6.  Update TCP/IP by reserving the following ports for WebSphere for
    z/OS:

       SOAP JMX Connector port                             - ${zSoapPort}
       ORB port                                            - ${zOrbListenerPort}
<!-- if (${zOrbListenerSslPort} != 0) -->
       ORB SSL port                                        - ${zOrbListenerSslPort}
<!-- endif -->
       Administrative console port                         - ${zAdminConsolePort}
       Administrative console secure port                  - ${zAdminConsoleSecurePort}

       HTTP Transport port                                 - ${zHttpTransportPort}
       HTTPS Transport port                                - ${zHttpTransportSslPort}

       Administrative local port                           - ${zAdminLocalPort}
       High availability manager communication port        - ${zHighAvailManagerPort}
       Service Integration port                            - ${zServiceIntegrationPort}
       Service Integration Secure port                     - ${zServiceIntegrationSecurePort}
       Service Integration MQ Interoperability port        - ${zServiceIntegrationMqPort}
       Service Integration MQ Interoperability Secure port - ${zServiceIntegrationSecureMqPort}
       Session Initiation Protocol (SIP) port              - ${zSessionInitiationPort}
       Session Initiation Protocol (SIP) secure port       - ${zSessionInitiationSecurePort}

       Administration Overlay UDP port                     - ${zAdminOverlayUDPPort}
       Administration Overlay TCP port                     - ${zAdminOverlayTCPPort}

       Daemon IP port                                      - ${zDaemonPort}
       Daemon SSL port                                     - ${zDaemonSslPort}

    View member BBOTCPIP in

    ${zTargetHLQ}.CNTL

<!-- start of changed text for TCPDD                                               -->

    Add the contents of this member to the PORT section of the file
    referenced by the DD statement for the TCP/IP profile in the
    TCP/IP start procedure. Cut and paste from this member into the
    data set used by your installation.

<!-- end of changed text for TCPDD                                                 -->

    ATTENTION: If another application has already reserved any of these
    ports for its own use, you must resolve the resulting conflict
    before you continue. Do not manually update the customization jobs
    and data files; instead, use the customization tools to regenerate
    the customization jobs, data, and instructions.

    Note:  It is recommended that the IPCONFIG, UDPCONFIG, and
    TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to
    only allow super users or APF-authorized user applications to bind
    to privileged ports (1-1024), unless the SAF keyword is specified
    and the user ID binding to the port is permitted to the SAF
    resource.  It is left up to the users' discretion to determine
    whether this is a viable course of action given the users' specific
    application/port requirements.

    For more information please consult:

    z/OS Communication Server IP Configuration Guide

    -------------------------------------------------------------------

7.  WebSphere for z/OS customization assumes that the following system
    data sets are in the system link list:

    Language Environment     SCEERUN
                             SCEERUN2

    System SSL               SIEALNKE

    Support for 64-bit       SCLBDLL2

    See the Language Environment Customization manual and the System
    SSL Programming manual for your z/OS release for advice on placing
    members from the libraries into the system link pack area.

    Placing these data sets in the link list insulates your WebSphere
    for z/OS configuration from changes in data set names (for example,
    when migrating to newer releases of z/OS).

    If the Language Environment or System SSL load module libraries are
    not in your system link list, you must perform the following steps
    before starting any WebSphere Application Server for z/OS servers:

    - Make sure the data sets are APF-authorized
    - Complete the optional step below to add the data sets to STEPLIB
      in the server JCL and setupCmdLine.sh script(s).

    If you regenerate server cataloged procedures at any point, make
    sure the data sets are added to the new cataloged procedures.

    -------------------------------------------------------------------

Running the customized jobs

---------------------------

The customization tools built a number of batch jobs with the
information you supplied. You must run the jobs in the order listed
below using user IDs with the appropriate authority.

<!-- import documents/cntl/fileSysUpdateAuth.txt -->

BEFORE YOU BEGIN: Complete the section above entitled "Doing manual
configuration updates".

Follow the table below, which lists in order the jobs you must submit
and the commands you must enter. Special handling notes are included
in the table. All jobs are members of

${zTargetHLQ}.CNTL

By default, the customization jobs below are generated with REGION=0M.
If this is not an allowable value on your target system, you may need to
modify this value for your environment.  Your system must allow a
private region of sufficient size to allow the running of a Java Virtual
Machine Region with a maximum heap specification of 256 Megabytes
(i.e., -Xmx256m).  Installation constraints that limit the region size
or system exits that restrict the region a job is running in, may cause
the customization jobs to fail due to a JVM error.  In the event of an
Out of Memory (OOM) failure due to inadequate native storage, you must
remove this constraint in order to successfully install WebSphere for
z/OS.

Attention: After submitting each job, carefully check the output.
Errors may exist even when all return codes are zero.

+-----------+----------------------------------------------------------+
|           | The BBOSBRAK and BBOSBRAM jobs do not need to be run if  |
|           | the indicated groups, user IDs and directories already   |
|           | exist with the correct gid, uid and ownership permission |
|           | values, as given below.                                  |
|           |                                                          |
|           | In order for RACF to automatically select an unused UID  |
|           | or GID value for WebSphere Application Server user IDs   |
|           | and groups:                                              |
|           |                                                          |
|           | - The RACF profile SHARED.IDS must be defined.           |
|           | - The RACF profile BPX.NEXT.USER must be define and used |
|           |   to indicate the ranges from which UID and GID values   |
|           |   are to be selected.                                    |
|           |                                                          |
|           | See the article "Preparing the Security Server (RACF)"   |
|           | in the WebSphere Application Server for z/OS online      |
|           | information center. For more information, consult        |
|           | Chapter 20, "RACF and z/OS Unix", in the z/OS Security   |
|           | Server RACF Security Administrator's Guide (SA22-7683).  |
|           |                                                          |
|           | Some of the customization jobs write temporary files     |
|           | to the /tmp directory. For each of these jobs, the       |
|           | customization process provides an alternate job that     |
|           | will write temporary files to the directory specified    |
|           | by the TMPDIR environment variable. If the TMPDIR        |
|           | environment variable is not defined, then the /tmp       |
|           | directory is used. These alternate jobs require a        |
|           | minimum WebSphere Application Server for z/OS service    |
|           | level of 8.5.5.0 on the target system. Refer to          |
|           | "Customizing your .profile" in the z/OS UNIX System      |
|           | Services User's Guide (SA22-7801-14) for information on  |
|           | defining environment variables.                          |
+-----------+----------------------------------------------------------+
| BBOSBRAK  |  User ID requirement: RACF special authority.            |
+-----------+                                                          |
| Done:     | This job executes the RACF commands to create common     |
|           | WebSphere for z/OS groups and user IDs                   |
| By:       |                                                          |
|           | Note: A uid or gid value of * indicates that the OS      |
|           | security system is to select an unused UID or GID value  |
|           |                                                          |
|           |  Administrator user ID:     ${zAdminUserid} (uid ${zAdminUid})      |
|           |  Control user ID:           ${zControlUserid} (uid ${zControlUid})      |
|           |  Servant user ID:           ${zServantUserid} (uid ${zServantUid}) |
|           |  Configuration group:       ${zConfigurationGroup} (gid ${zConfigurationGroupGID})      |
|           |  Servant group:             ${zServantGroup} (gid ${zServantGroupGID})      |
|           |  Local user group:          ${zLocalUserGroup} (gid ${zLocalUserGroupGID})      |
|           |                                                          |
|           | The commands are located in member BBOSBRAC of data set  |
|           | ${zTargetHLQ}.DATA.                                      |
|           |                                                          |
|           | Carefully review these definitions with your security    |
|           | administrator.                                           |
|           |                                                          |
|           | This job creates the WebSphere administrator ID ${zAdminUserid}|
|           | without a password (or password phrase).  You must       |
|           | assign this user ID a password (or password phrase) that |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           | complies with your institution standards. This is also   |
|           | the password (or password phrase) that will be used when |
|           | logging on to the WebSphere Application Server           |
|           | administrative console.                                  |
<!-- endif -->
<!-- if (${zAdminSecurityType} != websphereForZos) -->
|           | complies with your institution standards.                |
<!-- endif -->
|           |                                                          |
|           | Enter the following RACF command to assign a password:   |
|           |                                                          |
|           |   ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED   |
|           |                                                          |
|           | Enter the following RACF command to assign a             |
|           | password phrase:                                         |
|           |                                                          |
|           |   ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED    |
|           |                                                          |
|           | If you are using a different security system, make sure  |
|           | that the ${zAdminUserid} user ID has a password or       |
|           | password phrase.                                         |
|           |                                                          |
|           | To use RACF password phrase support, your target system  |
|           | must be at z/OS Version 1.9 or above.                    |
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |
|           | messages, from this job because a user ID, group  or     |
|           | profile is already defined.  Make sure the existing      |
|           | user ID, group or profile has the same characteristics   |
|           | as the user ID, group or profile being created by        |
|           | BBOSBRAK.                                                |
|           |                                                          |
|           | When this step is complete, all groups and user IDs      |
|           | listed above for job BBOSBRAK should be defined in the   |
|           | RACF database on each target system for the cell.        |
|           | Note: the WAS administrator user ID ${zAdminUserid} MUST have |
|           | the WAS configuration group ${zConfigurationGroup} as its default |
|           | OMVS group.                                              |
+-----------+----------------------------------------------------------+
| BBOSBRAM  | User ID requirement:                                     |
+-----------+     File system update authority (see above).            |
|           |                                                          |
| Done:     | This job creates home directories for WebSphere for z/OS |
|           | user IDS. These home directories will be subdirectories  |
|           | of ${zUserIDHomeDirectory}                                            |
| By:       |                                                          |
|           | This job will:                                           |
|           |                                                          |
|           | Create the following directory with permission bits 755: |
|           |                                                          |
|           |  ${zUserIDHomeDirectory}                                              |
|           |                                                          |
|           | Create the following directory with ownership            |
|           | ${zControlUserid}:${zConfigurationGroup} and permission bits 770:               |
|           |                                                          |
|           |  ${zUserIDHomeDirectory}/${zConfigurationGroup}                                     |
|           |                                                          |
|           | Create the following directory with ownership            |
|           | ${zControlUserid}:${zServantGroup} and permission bits 770:               |
|           |                                                          |
|           |  ${zUserIDHomeDirectory}/${zServantGroup}                                     |
|           |                                                          |
|           | Create the following directory with ownership            |
|           | ${zControlUserid}:${zLocalUserGroup} and permission bits 770:               |
|           |                                                          |
|           |  ${zUserIDHomeDirectory}/${zLocalUserGroup}                                     |
|           |                                                          |
|           | This job should be run on each z/OS system that will     |
|           | host WebSphere Application Server nodes using these      |
|           | WebSphere for z/OS common groups and owner user ID.      |
|           | After execution, verify that the directories have been   |
|           | created with the correct permissions on each system.     |
|           |                                                          |
|           | If these directories already exist with the specified    |
|           | ownership and permission on a target system, then this   |
|           | job does not need to be run on that system.              |
|           |                                                          |
|           | ATTENTION: If the directory                              |
|           |  ${zUserIDHomeDirectory}                                               |
|           | is used by applications other than WebSphere Application |
|           | Server, make sure that the permissions set by            |
|           | BBOSBRAM (755) are appropriate, or change them manually. |
|           | This directory must be world-readable for Websphere      |
|           | Application Server to run correctly.                     |
+-----------+----------------------------------------------------------+
| BBOCBRAK  | User ID requirement: RACF special authority.             |
+-----------+                                                          |
| Done:     | This job executes the RACF commands to create RACF users |
|           | and profiles required by this WebSphere for z/OS node.   |
| By:       |                                                          |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
|           | The following user ID(s) will be created:                |
<!-- endif -->
<!-- if (${zAdminSecurityType} != websphereForZos) -->
<!-- if (${zDaemonUserid}token != token) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
|           | The following user ID(s) will be created:                |
<!-- endif -->
<!-- if (${zDaemonUserid}token == token) -->
<!-- if (${zAdjunctUserid}token != token) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
|           | The following user ID(s) will be created:                |
<!-- endif -->
<!-- endif -->
<!-- endif -->
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           |  Unauthenticated user ID:   ${zAdminUnauthenticatedUserid} (uid ${zAdminUnauthenticatedUid}) |
<!-- endif -->
<!-- if (${zDaemonUserid}token != token) -->
|           |  Daemon user ID:            ${zDaemonUserid} (uid ${zDaemonUid}) |
<!-- endif -->
<!-- if (${zAdjunctUserid}token != token) -->
|           |  Adjunct user ID:           ${zAdjunctUserid} (uid ${zAdjunctUid}) |
<!-- endif -->
|           |                                                          |
|           | The commands are located in member BBOWBRAC of data set  |
|           | ${zTargetHLQ}.DATA.                                      |
|           |                                                          |
|           | Carefully review these definitions with your security    |
|           | administrator.                                           |
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |
|           | messages, from this job because a user ID, group  or     |
|           | profile is already defined.  Make sure the existing      |
|           | user ID, group or profile has the same characteristics   |
|           | as the user ID, group or profile being created by        |
|           | BBOCBRAK.                                                |
+-----------+----------------------------------------------------------+
| BBOMSGC   | User ID requirement: Update authority for data set       |
+-----------+ SYS1.MSGENU and/or SYS1.MSGJPN.                          |
| Done:     |                                                          |
|           | ATTENTION: This is optional unless you require message   |
|           | translation.                                             |
| By:       |                                                          |
|           | This job sets up MMS to translate messages for WebSphere |
|           | for z/OS.                                                |
|           |                                                          |
|           | Before running this job, update the INPUT DD statements  |
|           | to point to the SBBOMSG data set for your installation.  |
|           |                                                          |
|           | There are two steps to update: One that performs a copy  |
|           | to SYS1.MSGENU and one that performs a copy to           |
|           | SYS1.MSGJPN. Remove the unneeded step and if necessary,  |
|           | change the target libraries.                             |
+-----------+----------------------------------------------------------+
| --------  | Check user ID authorizations.                            |
+-----------+                                                          |
| Done:     | Make sure the ${zConfigurationGroup} group has read access to all     |
|           | WebSphere product data sets, as well as to any other     |
|           | data sets which will be placed in WebSphere for z/OS     |
|           | cataloged procedure STEPLIB concatenations.              |
|           |                                                          |
|           | Make sure the following user IDs have read access to     |
| By:       | the resolver configuration file in use on your system.   |
|           | Depending on your IP setup, this file may be             |
|           | /etc/resolv.conf, SYS1.TCPPARMS(TCPDATA), or another     |
|           | data set.                                                |
|           |                                                          |
|           | ${zControlUserid}                                                 |
|           | ${zServantUserid}                                                 |
|           |                                                          |
|           | See the z/OS eNetwork Communication Server IP            |
|           | Configuration manual for the resolver search order.      |
|           |                                                          |
|           | Ensure the following user ID has read access to the data |
|           | sets in your system parmlib concatenation:               |
|           |                                                          |
|           | ${zControlUserid}                                        |
<!-- if (${zDaemonUserid}token != token) -->
<!-- if (${zDaemonUserid} != ${zControlUserid}) -->
|           | ${zDaemonUserid}                                         |
<!-- endif -->
<!-- endif -->
|           |                                                          |
|           | ATTENTION:                                               |
|           |                                                          |
|           |  If operator commands are protected by the z/OS security |
|           |  server at your installation, you must ensure that       |
|           |  sufficient authority is given to WebSphere tasks to     |
|           |  control operations.                                     |
|           |                                                          |
|           |  The Application Server Controller user ID (${zControlUserid})     |
|           |  needs the ability to perform operations on started      |
|           |  tasks belonging to WebSphere Application Server for     |
|           |  z/OS.                                                   |
|           |                                                          |
|           |  Any user ID that is used to run the federation job      |
|           |  when the node agent is started automatically needs the  |
|           |  authority to issue the MVS START command.               |
|           |                                                          |
|           |  If you are currently controlling MVS console command    |
|           |  authority with SAF OPERCMDS profiles, grant the         |
|           |  following authorities as indicated, substituting your   |
|           |  own profile names:                                      |
|           |                                                          |
|           |  PERMIT  START_profile_name  CLASS(OPERCMDS)             |
|           |          ID (${zControlUserid})  ACCESS(UPDATE)          |
|           |                                                          |
|           |  PERMIT  STOP_profile_name  CLASS(OPERCMDS)              |
|           |          ID (${zControlUserid})  ACCESS(UPDATE)          |
|           |                                                          |
|           |  PERMIT  MODIFY_profile_name  CLASS(OPERCMDS)            |
|           |          ID (${zControlUserid})  ACCESS(UPDATE)          |
|           |                                                          |
|           |  PERMIT  CANCEL_profile_name  CLASS(OPERCMDS)            |
|           |          ID (${zControlUserid})  ACCESS(UPDATE)          |
|           |                                                          |
|           |  PERMIT  FORCE_profile_name  CLASS(OPERCMDS)             |
|           |          ID (${zControlUserid})  ACCESS(UPDATE)          |
|           |                                                          |
|           |  You must also grant the appropriate console command     |
|           |  authority to any user ID that executes the              |
|           |  startServer.sh or stopServer.sh script.                 |
|           |                                                          |
+-----------+----------------------------------------------------------+
| BBOWCFS   | User ID requirement:                                     |
+-----------+     File system update authority (see above), and the    |
|           |     authority to allocate                                |
| Done:     |        ${zConfigHfsName}                                 |
|           |                                                          |
|           | Before running this job:                                 |
| By:       |                                                          |
|           | Verify that the DD statement which defines the data set  |
|           | is valid for the storage rules defined on the target     |
|           | system.                                                  |
|           |                                                          |
|           | This job:                                                |
|           |                                                          |
|           | o   Creates a mount point directory                      |
|           |                                                          |
|           |     ${zConfigMountPoint}                                 |
|           |                                                          |
|           | o   Allocates the configuration file system              |
|           |                                                          |
|           |     ${zConfigHfsName}                                    |
|           |                                                          |
|           |     and mounts it at the above mount point.              |
|           |                                                          |
|           | Note: You can run job BBO855CA instead of BBOWCFS        |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855CA job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        |
|           | BBO855CA and BBOWCFS jobs are the same.                  |
|           |                                                          |
|           | DO NOT RUN THIS JOB IF:                                  |
|           |   1. The configuration file system already exists and is |
|           |      mounted at the desired mountpoint, or if            |
|           |                                                          |
|           |   2. The mount point directory is controlled by          |
|           |      automount.  Either disable the automount rule for   |
|           |      the configuration mount point while running this    |
|           |      job, or perform the following steps manually:       |
|           |                                                          |
|           |      a. Allocate the configuration file system data set. |
|           |      b. Issue the following shell commands, which will   |
|           |         also cause automount to mount the file system    |
|           |                                                          |
|           |      chmod 775 ${zConfigMountPoint}                      |
|           |                                                          |
|           |      chown ${zAdminUserid}:${zConfigurationGroup}        |
|           |        ${zConfigMountPoint}                              |
|           |                                                          |
|           | BEFORE YOU BEGIN: The BBOWCFS job assumes your root      |
|           | file system is mounted in read/write mode.  If the root  |
|           | file system is not mounted in read/write mode, manually  |
|           | create the directory                                     |
|           |                                                          |
|           | ${zConfigMountPoint}                                     |
|           |                                                          |
|           | and any needed higher directories, set file permissions  |
|           | to 775, and set the owning user ID and group to ${zAdminUserid}|
|           | and ${zConfigurationGroup} before running BBOWCFS.       |
|           |                                                          |
|           | EXAMPLE: If you plan to use /wasv8config as your         |
|           | directory, issue the following commands from within the  |
|           | OMVS shell:                                              |
|           |                                                          |
|           |   mkdir -p -m 775 /wasv8config                           |
|           |   chown -R ${zAdminUserid}:${zConfigurationGroup} /wasv8config|
|           |                                                          |
+-----------+----------------------------------------------------------+
| BBOWHFSA  | User ID requirement:                                     |
+-----------+     File system update authority (see above).            |
|           |                                                          |
| Done:     | This job populates the previously-created configuration  |
|           | file system and prepares it for profile creation.        |
| By:       |                                                          |
|           | Note: You can run job BBO855HA instead of BBOWHFSA       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855HA job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        |
|           | BBO855HA and BBOWHFSA jobs are the same.                 |
|           |                                                          |
|           | Note: If the SCEERUN data set is not in the system link  |
|           | list, add that data set to STEPLIB for the CHECKV step   |
|           | in BBOWHFSA.                                             |
|           |                                                          |
|           | Upon completion, examine the job output. Success is      |
|           | indicated with a RC=0 in the job output.                 |
|           |                                                          |
+-----------+----------------------------------------------------------+
| --------  | Verify the IBM SDK for Java selection.                   |
+-----------+                                                          |
|           | By default the WebSphere Application Server node will be |
| Done:     | configured to use the IBM SDK for Java 6 with 64-bit     |
|           | addressing. To configure with a different SDK enter the  |
|           | following commands:                                      |
|           |                                                          |
|           |   cd ${zConfigMountPoint}/                               |
|           |    ${zWasServerDir}/bin                                  |
|           |                                                          |
| By:       |   ./managesdk.sh -setNewProfileDefault -sdkName XXXXXX   |
|           |                                                          |
|           | where XXXXXX is set to one of the following values:      |
|           |                                                          |
|           |   1.6_31   (IBM SDK for Java 6 with 31-bit addressing)   |
|           |   1.6_64   (IBM SDK for Java 6 with 64-bit addressing)   |
|           |   1.7_31   (IBM SDK for Java 7 with 31-bit addressing)   |
|           |   1.7_64   (IBM SDK for Java 7 with 64-bit addressing)   |
|           |   1.7.1_31 (IBM SDK for Java 7.1 with 31-bit addressing) |
|           |   1.7.1_64 (IBM SDK for Java 7.1 with 64-bit addressing) |
|           |                                                          |
|           | Note that you must have the IBM WebSphere SDK for        |
|           | Java(TM) Technology Edition Version 7.0 or 7.1           |
|           | installed to specify one of the Java 7 or 7.1 SDKs.      |
|           | Use the following commands to determine which SDKs       |
|           | are available:                                           |
|           |                                                          |
|           |   cd ${zConfigMountPoint}/                               |
|           |    ${zWasServerDir}/bin                                  |
|           |                                                          |
|           |   ./managesdk.sh -listAvailable                          |
|           |                                                          |
+-----------+----------------------------------------------------------+
| BBOWWPFA  | User ID requirement:                                     |
+-----------+     File system update authority (see above).            |
|           |                                                          |
| Done:     | This job creates a profile (set of configuration files   |
|           | for a node) in the configuration file system.            |
| By:       |                                                          |
|           | Note: You can run job BBO855PA instead of BBOWWPFA       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855PA job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        |
|           | BBO855PA and BBOWWPFA jobs are the same.                 |
|           |                                                          |
|           | Note: If the SCEERUN2 data set is not in the system link |
|           | list, add that data set to STEPLIB for the LIBVSCRP and  |
|           | WPROFILE steps in BBOWWPFA.                              |
|           |                                                          |
|           | Upon completion, examine the job output. Success is      |
|           | indicated by rc=0.                                       |
|           |                                                          |
|           | Note: If the BBOWWPFA (profile creation job) fails, you  |
|           | must perform the following steps to remove the partially |
|           | built profile:                                           |
|           |                                                          |
|           |   cd ${zConfigMountPoint}/                               |
|           |    ${zWasServerDir}                                      |
|           |                                                          |
|           |   ./bin/manageprofiles.sh -deleteAll                     |
|           |                                                          |
|           |   rm -R profiles                                         |
|           |                                                          |
|           | Then, correct the problem that caused BBOWWPFA to fail   |
|           | and re-run the job                                       |
|           |                                                          |
+-----------+----------------------------------------------------------+
| BBOWPROC  | User ID requirement:                                     |
+-----------+     Authority to update the cataloged procedure library  |
| Done:     |     ${zProclibName}                                      |
|           |                                                          |
| By:       |                                                          |
|           | This job creates the tailored cataloged procedures and   |
|           | copies them to your procedure library.                   |
|           |                                                          |
|           | Note: You can run job BBO855RA instead of BBOWPROC       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855RA job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        |
|           | BBO855RA and BBOWPROC jobs are the same.                 |
|           |                                                          |
|           | ATTENTION: Be aware that you may overlay existing        |
|           | members in the above data set.                           |
|           |                                                          |
+-----------+----------------------------------------------------------+
| --------  | All WebSphere Application Server processes require       |
+-----------+ access to the Language Environment and System SSL load   |
| Done:     | modules.                                                 |
|           |                                                          |
| By:       | If the SCEERUN, SCEERUN2 and System SSL load module      |
|           | libraries are not in the system link list, add them to   |
|           | the STEPLIB DD concatenation in each of the following    |
|           | cataloged procedures in                                  |
|           | ${zProclibName}:                                         |
|           |                                                          |
|           |     ${zControlProcName}                                  |
|           |     ${zServantProcName}                                  |
|           |     ${zAdjunctProcName}                                  |
|           |     ${zDaemonProcName}                                   |
|           |                                                          |
|           | and also add the full data set names, separated by       |
|           | colons (:), to the STEPLIB variable in the shell script  |
|           |                                                          |
|           |     ${zConfigMountPoint}/                                |
|           |      ${zWasServerDir}/                                   |
|           |       profiles/default/bin/setupCmdLine.sh               |
|           |                                                          |
|           | When modifying the setupCmdLine.sh script, do not        |
|           | remove lines or comment them out, as this may cause      |
|           | problems with automated updates to the script.           |
|           |                                                          |
|           | Add only those data sets which are NOT in the link list. |
|           |                                                          |
+-----------+----------------------------------------------------------+
| --------  | Make sure Resource Recovery Services (RRS) is active.    |
+-----------+ (See the online information center for setup             |
| Done:     | instructions if necessary.) Look for the following       |
|           | console message to verify that RRS was successfully      |
|           | started:                                                 |
|           |                                                          |
| By:       |                                                          |
|           |   ASA2011I RRS INITIALIZATION COMPLETE. COMPONENT        |
|           |     ID=SCRRS                                             |
|           |                                                          |
+-----------+----------------------------------------------------------+
| --------  | If your system is busy, you may want to include a rule   |
+-----------+ in your WLM policy that OMVS work for job ${zServerShortName}       |
| Done:     | (such as the postinstaller step) is to run in a service  |
|           | class with a high service objective.                     |
| By:       |                                                          |
+-----------+----------------------------------------------------------+
| --------  | Start the Application Server                             |
+-----------+                                                          |
| Done:     | Issue the MVS command                                    |
|           |                                                          |
|           |   START ${zControlProcName},JOBNAME=${zServerShortName},                       |
|           |         ENV=${zCellShortName}.${zNodeShortName}.${zServerShortName}            |
|           |                                                          |
| By:       | This command starts the Application Server. Wait until   |
|           | the server is finished initializing before proceeding.   |
|           |                                                          |
|           | RESULT: The following message appears on the console and |
|           | in the job log of                                        |
|           |                                                          |
|           | ${zServerShortName}                                      |
|           |                                                          |
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |
|           |     z/OS CONTROL PROCESS ${zServerShortName}             |
<!-- if (${zInstallIVTApp}Token != falseToken) -->
+-----------+----------------------------------------------------------+
| BBOWIVT   | User ID requirement:                                     |
+-----------+     Any user ID defined to Unix System Services.         |
|           |                                                          |
| Done:     | This job runs the install verification test application. |
|           | See related topics in the WebSphere for z/OS Information |
| By:       | Center at:                                               |
|           |                                                          |
|           | http://www.ibm.com/software/webservers/appserv/zos_os390/|
|           | library/                                                 |
|           |                                                          |
|           | for information about how to run this job.               |
|           |                                                          |
<!-- endif -->
+-----------+----------------------------------------------------------+
| The application server is now configured.                            |
|                                                                      |
| To start the application server, issue the MVS command:              |
|                                                                      |
|   START ${zControlProcName},JOBNAME=${zServerShortName},             |
|         ENV=${zCellShortName}.${zNodeShortName}.${zServerShortName}  |
|                                                                      |
| To run this server in a reusable address space, add ",REUSASID=YES"  |
| to the end of the START command. See the article "Reusable address   |
| space" in the WebSphere Application Server for z/OS Information      |
| Center for more information, and important restrictions.             |
|                                                                      |
| To stop the location service daemon and associated application       |
| server(s), enter the MVS command:                                    |
|                                                                      |
|   STOP ${zDaemonJobName}                                             |
+----------------------------------------------------------------------+
