The deployment manager and application server nodes will be configured with:
The Profile Management Tool has created a response file based on the information you provided. These instructions tell you how to convert this response file into a set of customization jobs and how to run the jobs to customize WebSphere Application Server for z/OS. When you upload the customization jobs to the target system, a text version of these instructions will be written to:
${zTargetHLQ}.CNTL(BBODMINS)
${zTargetHLQ}.CNTL
${zTargetHLQ}.DATA
Use the Process action to create the customization jobs and upload them to the target z/OS system.
The Profile Management Tool does not attempt to update configuration data for your base operating system or existing subsystems. You need to perform the following manual steps prior to running the WebSphere for z/OS configuration jobs.
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the BLSCUSER member:
${zTargetHLQ}.CNTL(BBOIPCSP)
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following paritioned data set member to the SCHEDxx member:
${zTargetHLQ}.CNTL(BBOSCHED)
Note: When you are finished updating SCHEDxx, issue the command
SET SCH=xx to activate SCHEDxx and load a new program properties
table. This action does not need to be performed if the target z/OS system is
at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED member contains
already exists in the IBM-supplied PPT table at those z/OS levels.
SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),TYPE(0,30,70:79,88,89,120,245))
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zSoapPort} |
| Cell Discovery Address port | ${zCellDiscoveryPort} |
| ORB port | ${zOrbListenerPort} |
| ORB SSL port | ${zOrbListenerSslPort} |
| Administrative console port | ${zAdminConsolePort} |
| Administrative console secure port | ${zAdminConsoleSecurePort} |
| Admin local port | ${zAdminLocalPort} |
| High Availability Manager Communications port | ${zHighAvailManagerPort} |
| Middleware Agent RPC port | ${zMiddlewareAgentPort} |
| Administration Overlay UDP port | ${zAdminOverlayUDPPort} |
| Administration Overlay TCP port | ${zAdminOverlayTCPPort} |
| Status update listener port | ${zStatusListenerPort} |
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zNodeAgentJmxSoapConnectorPort} |
| Node Discovery port | ${zNodeAgentNodeDiscoveryPort} |
| Node Multicast Discovery Port | ${zNodeAgentNodeMulticastDiscoveryPort} |
| Node IPv6 multicast discovery port | ${zNodeAgentNodeIPv6MulticastDiscoveryPort} |
| ORB port | ${zNodeAgentOrbPortName} |
| Admin local port | ${zNodeAgentAdminLocalPort} |
| High Availability Manager Communication port | ${zNodeAgentHamCommPort} |
| Middleware Agent RPC port | ${zNodeAgentMiddlewareAgentPort} |
| Administration Overlay UDP port | ${zNodeAgentAdminOverlayUDPPort} |
| Administration Overlay TCP port | ${zNodeAgentAdminOverlayTCPPort} |
| ORB SSL port | ${zNodeAgentOrbSslPortName} |
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zAppServerSoapPort} |
| ORB port | ${zAppServerOrbListenerPort} |
| ORB SSL port | ${zAppServerOrbListenerSslPort} |
| Admin local port | ${zAppServerAdminLocalPort} |
| High availability manager communication port | ${zAppServerOrbListenerSslPort} |
| Service Integration port | ${zAppServerServiceIntegrationPort} |
| Service Integration Secure port | ${zAppServerServiceIntegrationSecurePort} |
| Service Integration MQ Interoperability port | ${zAppServerServiceIntegrationMqPort} |
| Service Integration MQ Interoperability Secure port | ${zAppServerServiceIntegrationSecureMqPort} |
| Session Initiation Protocol (SIP) port | ${zAppServerSessionInitiationPort} |
| Session Initiation Protocol (SIP) secure port | ${zAppServerSessionInitiationSecurePort} |
| Administration Overlay UDP port | ${zAppServerAdminOverlayUDPPort} |
| Administration Overlay TCP port | ${zAppServerAdminOverlayTCPPort} |
| Type | Number |
|---|---|
| Daemon IP port | ${zDaemonPort} |
| Daemon SSL port | ${zDaemonSslPort} |
Add the following contents to the PORT section of the TCP/IP profile that is used by the TCP/IP start procedure.
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the PORT section of the TCP/IP profile:
${zTargetHLQ}.CNTL(BBOTCPIC)
Attention: If another application has already reserved any of these ports for its own use, you must resolve the resulting conflict before you continue. If you use the Profile Management Tool to update the port specifications, be sure to upload the updated customization jobs.
Note: It is recommended that the IPCONFIG, UDPCONFIG, and TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to only allow super users or APF-authorized user applications to bind to privileged ports (1-1024), unless the SAF keyword is specified and the user ID binding to the port is permitted to the SAF resource. It is left up to the users' discretion to determine whether this is viable course of action given the users' specific application/port requirements. For more information please consult: z/OS Communication Server IP Configuration Guide.
See the Language Environment Customization manual and the System SSL Programming manual for your z/OS release for advice on placing members from the libraries into the system link pack area.
Placing these data sets in the link list insulates your WebSphere Application Server for z/OS configuration from changes in data set names (for example, when migrating to newer releases of z/OS).
If the Language Environment or System SSL load module libraries are not in your system link list, you need to perform the following steps before starting any WebSphere Application Server for z/OS servers:
The Profile Management Tool built a number of batch jobs with the variables you supplied. You need to run the jobs in the order listed below, using user IDs with the appropriate authority.
Before you begin: Complete the section above entitled "Manual configuration updates".
| Type | Group/userid | GID/UID |
|---|---|---|
| Administrator user ID | ${zAdminUserid} | ${zAdminUid} |
| Control user ID | ${zControlUserid} | ${zControlUid} |
| Servant user ID | ${zServantUserid} | ${zServantUid} |
| Configuration group | ${zConfigurationGroup} | ${zConfigurationGroupGID} |
| Servant group | ${zServantGroup} | ${zServantGroupGID} |
| Local user group | ${zLocalUserGroup} | ${zLocalUserGroupGID} |
Carefully review these definitions with your security administrator.
ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED
ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED
Result: You may receive errors, such as INVALID USER messages, from this job because a user ID, group or profile is already defined. Make sure the existing user ID, group, or profile has the same characteristics as the user ID, group, or profile being created by BBOSBRAK. If not, then change the values in the Profile Management Tool, which are causing the conflict. Then upload the updated customization jobs and restart the process.
When this step is complete, all groups and user IDs
listed above for job BBOSBRAK should be defined in the
RACF database on each target system for the cell.
Note: The WebSphere Application Server administrator user ID
${zAdminUserid} must have the WebSphere Application Server
configuration group ${zConfigurationGroup} as its
default OMVS group.
User ID requirement: File system update authority (see above).
This job creates home directories for WebSphere Application Server for z/OS user IDS. These home directories will be subdirectories of ${zUserIDHomeDirectory}
This job will create the following directories:
${zUserIDHomeDirectory}
ownership: (any)
permission bits: 755
${zUserIDHomeDirectory}/${zConfigurationGroup}
ownership: ${zControlUserid}:${zConfigurationGroup}
permission bits: 770
${zUserIDHomeDirectory}/${zServantGroup}
ownership: ${zControlUserid}:${zServantGroup}
permission bits: 770
${zUserIDHomeDirectory}/${zLocalUserGroup}
ownership: ${zControlUserid}:${zLocalUserGroup}
permission bits: 770
This job should be run on each z/OS system that will host WebSphere Application Server nodes using these WebSphere Application Server for z/OS common groups and owner user ID. After execution, verify that the directories have been created with the correct permissions on each system.
If these directories already exist with the specified ownership and permission on a target system, then this job does not need to be run on that system.
Attention: If the directory ${zUserIDHomeDirectory} is used by applications other than WebSphere Application Server, make sure that the permissions set by BBOSBRAM (755) are appropriate, or change them manually. This directory must be world-readable for Websphere Application Server to run correctly.
This job executes the RACF commands to create RACF users and profiles required
by this WebSphere for z/OS cell.
These commands are located in
Carefully review these definitions with your security administrator.
Result: You may receive errors, such as INVALID USER
messages, from this job because a user ID, group or
profile is already defined. Make sure the existing
user ID, group or profile has the same characteristics
as the user ID, group or profile being created by
BBODBRAK. If not, then change the values in the
Profile Management Tool which are causing the conflict,
upload the updated customization jobs, and restart the process.
This job executes the RACF commands to create RACF users and profiles required
by this WebSphere for z/OS cell.
These commands are located in
| Type | Userid | UID |
|---|
| Type | Userid | UID |
|---|
| Type | Userid | UID |
|---|---|---|
| Unauthenticated user ID | ${zAdminUnauthenticatedUserid} | ${zAdminUnauthenticatedUid} |
| Daemon user ID | ${zDaemonUserid} | ${zDaemonUid} |
| Adjunct user ID | ${zAdjunctUserid} | ${zAdjunctUid} |
Carefully review these definitions with your security administrator.
Result: You may receive errors, such as INVALID USER
messages, from this job because a user ID, group or
profile is already defined. Make sure the existing
user ID, group or profile has the same characteristics
as the user ID, group or profile being created by
BBOCBRAK. If not, then change the values in the
Profile Management Tool which are causing the conflict,
upload the updated customization jobs, and restart the process.
Make sure the ${zConfigurationGroup} group has read access to all WebSphere product data sets, as well as to any other data sets which will be placed in WebSphere Application Server for z/OS cataloged procedure STEPLIB concatenations.
Make sure the following user IDs have read access to
the resolver configuration file in use on your system.
Depending on your IP setup, this file may be
/etc/resolv.conf, SYS1.TCPPARMS(TCPDATA), or another
data set.
See the z/OS eNetwork Communication Server IP Configuration manual for the resolver search order.
Ensure the following user ID has read access to the data
sets in your system parmlib concatenation:
Attention: If operator commands are protected by the z/OS security server at your installation, you must ensure that sufficient authority is given to WebSphere tasks to control operations.
The Deployment Manager and Application Server controller user ID (${zControlUserid}) needs the ability to perform operations on started tasks belonging to WebSphere Application Server for z/OS.
Any user ID that is used to run a federation job when the node agent is started automatically needs the authority to issue the MVS START command.
If you are currently controlling MVS console command
authority with SAF OPERCMDS profiles, grant the
following authorities as indicated, substituting your
own profile names:
You need to also grant the appropriate console command authority to any user ID that executes the startServer.sh or stopServer.sh script.
Before running this job: Verify that the DD statements which define
the data sets are valid for the storage rules defined on the target system.
This job:
Creates the following mount point directories
Allocates the following configuration file system(s) using the Hierarchical File System (HFS)
${zConfigHfsName}
${zAppServerConfigHfsName}
Allocates the following configuration file system(s) using the z/OS Distributed File Service zSeries File System (zFS)
${zConfigHfsName}
${zAppServerConfigHfsName}
Allocates the following configuration file system using the Hierarchical File System (HFS) ${zAppServerConfigHfsName}
Allocates the following configuration file system
using the z/OS Distributed File Service zSeries File
System (zFS)
${zAppServerConfigHfsName}
and mounts them at the above mount points.
Note: You can run job BBO855CC instead of BBOCCFS if the
target WebSphere Application Server for z/OS installation image is at least
at the 8.5.5.0 service level. The BBO855CC job will use the directory
specified by the TMPDIR environment variable, if defined, for temporary
files. The user ID requirements for the BBO855CC and BBOCCFS jobs are the same.
Do not run this job if:
Note: You can run job BBO855HC instead of BBOCHFSA if the
target WebSphere Application Server for z/OS installation image is at least
at the 8.5.5.0 service level. The BBO855HC job will use the directory
specified by the TMPDIR environment variable, if defined, for temporary
files. The user ID requirements for the BBO855HC and BBOCHFSA jobs are the same.
Note: If the SCEERUN data set is not in the system link
list, add that data set to STEPLIB for the CHECKV step
in BBOCHFSA.
When this completes, examine the job output. Success is
indicated with a RC=0 in the job output.
By default the WebSphere Application Server nodes will be configured to use the IBM SDK for Java 6 with 64-bit addressing. To configure the deployment manager node with a different SDK enter the following commands:
cd ${zConfigMountPoint}/${zWasServerDir}/bin
./managesdk.sh -setNewProfileDefault -sdkName XXXXXX
where XXXXXX is set to one of the following values:
1.6_31 (IBM SDK for Java 6 with 31-bit addressing)
1.6_64 (IBM SDK for Java 6 with 64-bit addressing)
1.7_31 (IBM SDK for Java 7 with 31-bit addressing)
1.7_64 (IBM SDK for Java 7 with 64-bit addressing)
1.7.1_31 (IBM SDK for Java 7.1 with 31-bit addressing)
1.7.1_64 (IBM SDK for Java 7.1 with 64-bit addressing)
To configure the application server node with a different SDK enter the
following commands:
cd ${zAppServerConfigMountPoint}/${zAppServerWasServerDir}/bin
./managesdk.sh -setNewProfileDefault -sdkName XXXXXX
where XXXXXXX is set to one of the above values.
Note that you must have the IBM WebSphere SDK for Java(TM) Technology Edition Version 7.0 or 7.1 installed to specify one of the Java 7 or 7.1 SDKs. Use the following commands to determine which SDKs are available for the deployment manager node:
cd ${zConfigMountPoint}/${zWasServerDir}/bin
./managesdk.sh -listAvailable
Use the following commands to determine which SDKs are available for the
application server node:
cd ${zAppServerConfigMountPoint}/${zAppServerWasServerDir}/bin
./managesdk.sh -listAvailable
Note: You can run job BBO855PC instead of BBOWWPFC if the
target WebSphere Application Server for z/OS installation image is at least
at the 8.5.5.0 service level. The BBO855PC job will use the directory
specified by the TMPDIR environment variable, if defined, for temporary
files. The user ID requirements for the BBO855PC and BBOWWPFC jobs are the same.
Note: If the SCEERUN2 data set is not in the system link
list, add that data set to STEPLIB for the LIBVSCRP,
CELPROFD and CELPROFN steps in BBOWWPFC
Upon completion, examine the job output. Success is
indicated by rc=0.
Note: If the BBOWWPFC (profile creation) job fails, you must
perform the following steps to clean up the partially-built profiles
for both the deployment manager and application server:
cd ${zConfigMountPoint}/${zWasServerDir}
./bin/manageprofiles.sh -deleteAll
rm -R profiles
cd ${zAppServerConfigMountPoint}/${zAppServerWasServerDir}
./bin/manageprofiles.sh -deleteAll
rm -R profiles
Then correct the problem that caused BBOWWPFC to fail and re-run the job.
Note: You can run job BBO855RC instead of BBOCPROC if the
target WebSphere Application Server for z/OS installation image is at least
at the 8.5.5.0 service level. The BBO855RC job will use the directory
specified by the TMPDIR environment variable, if defined, for temporary
files. The user ID requirements for the BBO855RC and BBOCPROC jobs are the same.
Attention: Be aware that you may overlay existing
members in the above data set.
${zConfigMountPoint}/${zWasServerDir}/profiles/default/bin/setupCmdLine.sh
${zAppServerConfigMountPoint}/${zAppServerWasServerDir}/profiles/default/bin/setupCmdLine.sh
When modifying the setupCmdLine.sh script, do not
remove lines or comment them out, as this may cause
problems with automated updates to the script.