<!-- ================================================================ -->         
<!-- PROPRIETARY-STATEMENT:                                           -->         
<!-- Licensed Material - Property of IBM                              -->         
<!--                                                                  -->         
<!-- 5724-I63, 5724-H88, 5655-N01, 5733-W61                           -->         
<!-- (C) Copyright IBM Corp. 1999, 2012                               -->         
<!-- All Rights Reserved                                              -->         
<!-- US Government Users Restricted Rights - Use, duplication or      -->         
<!-- disclosure restricted by GSA ADP Schedule Contract with IBM Corp.-->         
<!-- ================================================================ -->         
<!--                                                                  -->         
<!-- Change Activity:                                                 -->         
<!--                                                                  -->         
<!--   240619  H28W600 111504  PDML: Initial release.                 -->         
<!--   246983  H28W600 121604    DB: Updates based on new product     -->         
<!--                                 dataset panels                   -->         
<!--   246865  H28W601 011005    DB: Updates for managed nodes        -->         
<!--   249091  H28W601 011005    DB: Updates based on review comments -->         
<!--   247922  H28W601 011905    DB: Fix some typos                   -->         
<!--   251673  H28W601 012605    DB: More review updates              -->         
<!--   252044  H28W601 012705    DB: Some usability changes           -->         
<!--   253951  H28W601 021705    DB: Add BBOMCFGW to instructions     -->         
<!--   257033  H28W601 022205    DB: Add BBOMBRAJ and BBOMBRAK        -->         
<!--   257024  H28W601 022305    DB: fix max length problem           -->         
<!--   241041  H28W601 032205  PDSS: Added instructions for when      -->         
<!--                                 BBOWWPFM fails on second try     -->         
<!--   259928  H28W602 041405    DB: Only  generate BBORTSS5 section  -->         
<!--                                 if answer for in STEPLIB is Y    -->         
<!--   265249  H28W602 041805    DB: BBOWMNAN needs admin id not UID=0-->         
<!--   271696  H28W602 042805    DB: remove BBOMCFGW                  -->         
<!--   262809  H28W602 042805    DB: remove WLM static instructions   -->         
<!--   279429  H28W602 052705  PDML: add directory verifications step.-->         
<!--   281074  H28W602 060305  PDML: display the dir verfication step -->         
<!--                                 only if USERHOME is not tmp.     -->         
<!--   283304  H28W602 061305  PDML: remove the dir verfication step. -->         
<!--  PK07374  H28W602 062105  PDML: add directory verifications step.-->         
<!--  PK07293  H28W602 062205    DB: fix START command for nodeagent  -->         
<!--   290470  H28W602 071805  PDML: remove BBOSGSK and SYSEXEC.      -->         
<!-- LIDB2634  H28W610 083005  PDML: security out of box update.      -->         
<!--   307522  H28W610 092205    DB: Make START instructions more     -->         
<!--                                 generic                          -->         
<!--   311865  H28W610 100805    DB: Remove references to SCEERUN     -->         
<!--   313366  H28W610 101405  PDML: move text around ERRLOG.         -->         
<!--   317828  H28W610 111205  PDML: add OMVS WLM setup instructions. -->         
<!--   323701  H28W610 112105    DB: move RRS instructions prior to   -->         
<!--                                 federation                       -->         
<!--   325782  H28W610 112105    DB: change BBORTSS5 to BBORTS61      -->         
<!--   330776  H28W610 121405    DB: update instructions based on     -->         
<!--                                 change to SBBOLPA/SBBOLOAD       -->         
<!--   337853  H28W610 011206    DB: fix some typos                   -->         
<!--   333384  H28W610 011306    DB: add zfs support                  -->         
<!--  333384.1 H28W610 011906    DB: filesystem should be two words   -->         
<!--  337515   H28W610 012306    DB: updates for STEPLIB changes      -->         
<!--  330804   H28W610 012406    DB: add automount warning            -->         
<!--  342400   H28W610 013006    DB: change FILEZFS to FSTYPE         -->         
<!--  338949   H28W610 013006    DB: update SMF instructions          -->         
<!--  342461   H28W610 013106    DB: update OPERCMDs instructions     -->         
<!--  338132   H28W610 020606  PDML: add SBBGLOAD.                    -->         
<!--  354688   H28W610 031406    DB: LE/SSL datasets don't go in LPA  -->         
<!--  356728   H28W610 032406    DB: use ASFSTYPE                     -->         
<!-- 357672.2  H28W610 032706    DB: add IPv6 node multicast port     -->         
<!-- PK20049   H28W610 042206    DB: instructions for LE in STEPLIB   -->         
<!--  364931   H28W610 042406    DB: updates for non root install     -->         
<!--  348320   H28W610 102506    DB: updates for asterisk id          -->         
<!--  400982   H28W610 102606    DB: Add text for AUTOMOVE            -->         
<!--  402402   H28W610 110106    DB: Reword AUTOMOVE text             -->         
<!--  411108   H28W610 121206    DB: Fix possible length error        -->         
<!--  412596   H28W610 010307    DB: Add SBBGLOAD references          -->         
<!--  412597   H28W610 010807    DB: fix minor text issues            -->
<!-- LIDB4489-16 H28W700 040107  DB: 64-bit updates                   -->
<!--  425357   H28W610 040907    DB: use aggrgrow option for ZFS      -->         
<!--  447303   V7.0    070614  PDOP: Userid simplification            -->
<!--  447258   V7.0    20070629 PXT: Convert zmpt variables           --> 
<!-- LIDB4194-52 V7.0  070907  PDOP: Flexible management              -->
<!--LIDB4302-11.10 V7.0    070824    DB: Rename file system job       -->
<!--  465452   V7.0    101907  PDOP: Updated profile cleanup info     -->
<!--  LIDB4689  V7.0    20071024 DMB: Move load modules to hfs        -->
<!--  466649   V7.0    102507  PDOP: Remove refs to config dialog     -->
<!--  484621   V7.0    112807  PDOP: Updated "Z" proclib references   -->
<!--  489808   V7.0    122007   PXT: Change order of BBOWCPYM to run  -->
<!--  492063   V7.0    011507   DMB: Use one step RACF jobs           -->
<!--  502633   V7.0    030308  PDOP: Removed use of "InfoCenter"      -->
<!--  504724   V7.0    031508  PDOP: Added prod file system directions-->
<!--  467454   V7.0    032608  PDOP: Use of RMI connector for addNode -->
<!--  500745   V7.0    20080407 PXT: Rename from BBOMBRAJ to BBOMBRAK -->
<!--511429.1 V7.0   20080519   DMB: Create SR id in bbosbrac          -->
<!--  538461   V7.0   20080723 PDOP: Add SCLBDLL2 to system link list -->
<!--  540011   V7.0   20080724 DMB: Add adjunct id                    -->
<!--  546577   V7.0   20080829 PDOP: Add daemon id                    -->
<!--  567032   V7.0   20081203 PDOP: Clean up                         -->
<!--  PK70886  V7.0   20081216  DMB: Add region size warning info     -->
<!--  567032.1 V7.0   20090116 PDOP: Additional clean up              -->
<!-- PK83899   V7.0   20090413 DMB: Update section on SCHEDxx member  -->
<!-- PK84830   V7.0	  20080422 DMB: Remove keyring reference in       -->
<!--                                BBOWMNAN section, and reword it   -->
<!-- F908-13390.2 V8.0 200907xx DMB: BPXPRMxx updates for noautomove  -->
<!-- PK94663  V7.0     20090922  DMB: Update BBOMSGC step             -->
<!-- PM12309  V7.0    20100721 DMB: Updates for REUSASID              -->
<!-- F908-32216 V8.0  20100911 PDOP: Replace BBOMCPY1 with BBOMPROC   -->
<!-- 688594     V8.0  20110130 PDOP: Change "v7" to "v8"              -->
<!-- 715560     V8.0  20110908 PDOP: Show WAS version                 -->
<!-- F43152-51709.2 V8.5 20111013 PDOP: V8.5 release basics           -->
<!-- F43152-56172   V8.5 20111228 PDOP: Add VE ports                  --> 
<!-- 725442         V8.5 20120106 PDOP: Added SDK selection           -->
<!-- 730602         V8.5 20120309 PDOP: Remove admin asynch references-->
<!-- 739067       V8.5.5 20121206 PDOP: TMPDIR support                -->
<!-- 745081       V7.0   20130306 PDOP: Update SAF profile privileges --> 
<!-- 756277       V8.5.5 20140221 PDDH: Add Java 7.1 to cust. instr.  -->        
<!-- ================================================================ -->         
                                                                                                                                                               
-----------------------------------------------                                 
WebSphere Application Server for z/OS V8.5 customization instructions:

Managed application server node ${zNodeShortName}   
Deployment manager:
  ${zFederateDmaNodeHostName}, port ${zFederateDmaPort}     
Tailored on ${ZDATE} at ${ZTIMEL} by ${ZUSER}
WCT version ${wctVersion} build ${wctBuild} 
                                                                                                                                                               
The customization tools have created jobs based on the information you          
provided. These instructions tell you how to modify the operating               
system and run the jobs to customize WebSphere for z/OS.                        
                                                                                                                                                              
RULES:                                                                          
                                                                                                                                                               
1.  If you created the target data sets (*.CNTL and *.DATA) on another          
    (driving) system, you must copy them to the target system and give          
    them the same data set names.                                               
                                                                                                                                                               
2.  You must perform these instructions on your target system.                  
                                                                                                                                                               
Doing manual configuration updates                                              
                                                                                
----------------------------------                                              
                                                                                                                                                               
You must perform the following manual steps on the target z/OS system 
before running the WebSphere for z/OS configuration jobs.  
                                                                                                                                                        
1.  Update BLSCUSER. Refer to member BBOIPCSP in                                
                                                                        
    ${zTargetHLQ}.CNTL                                                                  
                                                                         
    In order to use the IPCS support provided by the product, append            
    the contents of this member to the BLSCUSER member in your IPCSPARM         
    or system PARMLIB datasets.                                                 
                                                                                                                                                              
    -------------------------------------------------------------------         
                                                                                                                                                          
2.  Update SCHEDxx. Refer to member BBOSCHED in                                 
                                                                         
    ${zTargetHLQ}.CNTL                                                                   
                                                                         
    In order to set the correct program properties for the WebSphere            
    for z/OS run-time executables, append the contents of this member           
    to the SCHEDxx member in your system PARMLIB concatenation.                 
                                                                        
    Note: When you are finished, issue the command SET SCH=xx to
    activate SCHEDxx and load a new program properties table.  This
    action does not need to be performed if the target z/OS system is
    at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED
    member contains already exists in the IBM-supplied PPT table at
    those z/OS levels.               

    -------------------------------------------------------------------         
                                                                        
3.  If you want to collect the SMF120 records created by the run-time           
    servers, update SMFPRMxx via the following:                                 
                                                                                                                                                             
    EXAMPLE:                                                                    
                                                                                                                                                              
       SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),                    
                          TYPE(0,30,70:79,88,89,120,245))                       
                                                ---                             
                                                                         
    For details on the SMF records, see related topics in the                   
    WebSphere for z/OS Information Center at                                    
    http://www.ibm.com/software/webservers/appserv/zos_os390/library/           
                                                                              
    -------------------------------------------------------------------         
                                                                                                                                                          
<!-- import documents/cntl/productFileSystem.txt -->
                                                                                
    -------------------------------------------------------------------         
                                                                                                                                                          
5.  Update your active BPXPRMxx member to have the following WebSphere          
    for z/OS configuration file system:                                         
                                                                        
    ${zConfigHfsName}                                                                   
                                                                        
    mounted at:                                                                 
                                                                        
    ${zConfigMountPoint}                                                                  
                                                                        
    in read/write mode.                                                         
                                                                                                                                                               
    EXAMPLE:                                                                    
                                                                          
<!-- if (${zFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                
          TYPE(${zFilesystemType})                                                     
          MODE(RDWR) PARM('AGGRGROW') NOAUTOMOVE
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                
          TYPE(${zFilesystemType})                                                      
          MODE(RDWR) NOAUTOMOVE
<!-- endif -->
                                                                 
    The NOAUTOMOVE parameter in the example above prevents the                  
    configuration file system from being mounted on a different z/OS            
    system in a shared file system configuration, which could cause             
    performance problems.

<!-- if (${zFilesystemType} == ZFS) -->
    If you have specified "aggrgrow=on" in your IOEFSPRM parmlib member,
    you can omit the AGGRGROW parm shown in the above examples
<!-- endif -->    
                                                                                                                                                 
    -------------------------------------------------------------------         
                                                                          
6.  Update TCP/IP by reserving the following ports for WebSphere for            
    z/OS.  These will be used during the federation process of your             
    managed node.                                                               
                                                                                                                                                             
       SOAP JMX Connector port                      - ${zFederateJmxSoapConnectorPort}                  
       Node Discovery port                          - ${zFederateNodeDiscoveryPort}                
       Node Multicast Discovery Port                - ${zFederateNodeMulticastDiscoveryPort}                
       Node IPv6 multicast discovery port           - ${zFederateNodeIPv6MulticastDiscoveryPort}                
       Node Agent's ORB port                        - ${zFederateOrbPortName}                  
       Administrative local port                    - ${zFederateAdminLocalPort}                  
       High Availability Manager Communication port - ${zFederateHamCommPort}                
<!-- if (${zFederateOrbSslPortName} != 0) -->
       Node Agent's ORB SSL port                    - ${zFederateOrbSslPortName}                
<!-- endif -->
       Middleware Agent RPC port                    - ${zMiddlewareAgentPort}
       Administration Overlay UDP port              - ${zAdminOverlayUDPPort}
       Administration Overlay TCP port              - ${zAdminOverlayTCPPort}
                                                                        
    View member BBOTCPIM in                                                     
                                                                       
    ${zTargetHLQ}.CNTL                                                                  
                                                                        
    Add the contents of this member to the PORT section of the file             
    referenced by the DD statement for the TCP/IP profile in the                
    TCP/IP start procedure. Cut and paste from this member into the             
    data set used by your installation.                                         
                                                                                                                                                        
    ATTENTION: If another application has already reserved any of these         
    ports for its own use, you must resolve the resulting conflict              
    before you continue. Do not manually update the customization jobs
    and data files; instead, use the customization tools to regenerate      
    the customization jobs, data, and instructions.                    

    ATTENTION: Skip this step if the ports are already defined in the           
    TCP/IP profile.                                                             

    -------------------------------------------------------------------         
                                                                       
7.  WebSphere for z/OS customization assumes that the following system          
    data sets are in the system link list:                                      
                                                                        
    Language Environment     SCEERUN                                            
                             SCEERUN2                                           
                                                                       
    System SSL               SIEALNKE
    
    Support for 64-bit       SCLBDLL2
                                                                        
    See the Language Environment Customization manual and the System            
    SSL Programming manual for your z/OS release for advice on placing          
    members from the libraries into the system link pack area.                  
                                                                       
    Placing these data sets in the link list insulates your WebSphere           
    for z/OS configuration from changes in data set names (for example,         
    when migrating to newer releases of z/OS).                                                
                                                                       
    If the Language Environment or System SSL load module libraries are         
    not in your system link list, you must perform the following steps          
    before starting any WebSphere Application Server for z/OS servers:          
                                                                    
    - Make sure the data sets are APF-authorized                                
    - Complete the optional step below to add the data sets to STEPLIB          
      in the server JCL and setupCmdLine.sh script(s).                          
                                                                    
    If you regenerate server cataloged procedures at any point, make            
    sure the data sets are added to the new cataloged procedures.               
                                                                         
Running the customized jobs                                                     
                                                                                
---------------------------                                                     
                                                                                                                                                              
The customization tools built a number of batch jobs with the                  
information you supplied. You must run the jobs in the order listed               
below using user IDs with the appropriate authority.                            
                                                                       
<!-- import documents/cntl/fileSysUpdateAuth.txt -->
                                                                                
BEFORE YOU BEGIN: Complete the section above entitled "Doing manual             
configuration updates."                                                         
                                                                                                                                                             
Follow the table below, which lists in order the jobs you must submit           
and the commands you must enter. Special handling notes are included            
in the table. All jobs are members of                                           
                                                                                                                                                           
${zTargetHLQ}.CNTL

By default, the customization jobs below are generated with REGION=0M.  
If this is not an allowable value on your target system, you may need to
modify this value for your environment.  Your system must allow a       
private region of sufficient size to allow the running of a Java Virtual
Machine Region with a maximum heap specification of 256 Megabytes       
(i.e., -Xmx256m).  Installation constraints that limit the region size  
or system exits that restrict the region a job is running in, may cause 
the customization jobs to fail due to a JVM error.  In the event of an  
Out of Memory (OOM) failure due to inadequate native storage, you must    
remove this constraint in order to successfully install WebSphere for   
z/OS.                                                                   
                                                                                                                                                                
Attention: After submitting each job, carefully check the output.               
Errors may exist even when all return codes are zero.                           

+-----------+----------------------------------------------------------+        
|           | The BBOSBRAK and BBOSBRAM jobs do not need to be run if  |
|           | the indicated groups, user IDs and directories already   |
|           | exist with the correct gid, uid and ownership permission |
|           | values, as given below.                                  |        
|           |                                                          |        
|           | In order for RACF to automatically select an unused UID  |        
|           | or GID value for WebSphere Application Server user IDs   |        
|           | and groups:                                              |        
|           |                                                          |        
|           | - The RACF profile SHARED.IDS must be defined.           |        
|           | - The RACF profile BPX.NEXT.USER must be define and used |        
|           |   to indicate the ranges from which UID and GID values   |        
|           |   are to be selected.                                    |        
|           |                                                          |        
|           | See the article "Preparing the Security Server (RACF)"   |        
|           | in the WebSphere Application Server for z/OS online      |
|           | information center. For more information, consult        |
|           | Chapter 20, "RACF and z/OS Unix", in the z/OS Security   |
|           | Server RACF Security Administrator's Guide (SA22-7683).  |        
|           |                                                          |
|           | Some of the customization jobs write temporary files     |
|           | to the /tmp directory. For each of these jobs, the       |
|           | customization process provides an alternate job that     |
|           | will write temporary files to the directory specified    |
|           | by the TMPDIR environment variable. If the TMPDIR        |
|           | environment variable is not defined, then the /tmp       |
|           | directory is used. These alternate jobs require a        |
|           | minimum WebSphere Application Server for z/OS service    |
|           | level of 8.5.5.0 on the target system. Refer to          | 
|           | "Customizing your .profile" in the z/OS UNIX System      | 
|           | Services User's Guide (SA22-7801-14) for information on  |
|           | defining environment variables.                          |   
+-----------+----------------------------------------------------------+        
| BBOSBRAK  |  User ID requirement: RACF special authority.            |        
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create common     |
|           | WebSphere for z/OS groups and user IDs                   |
| By:       |                                                          |
|           | Note: A uid or gid value of * indicates that the OS      |        
|           | security system is to select an unused UID or GID value  |        
|           |                                                          |
|           |  Administrator user ID:     ${zAdminUserid} (uid ${zAdminUid})      |
|           |  Control user ID:           ${zControlUserid} (uid ${zControlUid})      |
|           |  Servant user ID:           ${zServantUserid} (uid ${zServantUid}) |
|           |  Configuration group:       ${zConfigurationGroup} (gid ${zConfigurationGroupGID})      |        
|           |  Servant group:             ${zServantGroup} (gid ${zServantGroupGID})      |        
|           |  Local user group:          ${zLocalUserGroup} (gid ${zLocalUserGroupGID})      |       
|           |                                                          |        
|           | The commands are located in member BBOSBRAC of data set  |        
|           | ${zTargetHLQ}.DATA.                                      |        
|           |                                                          |        
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | This job creates the WebSphere administrator ID ${zAdminUserid}|        
|           | without a password (or password phrase).  You must       |
|           | assign this user ID a password (or password phrase) that |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           | complies with your institution standards. This is also   |
|           | the password (or password phrase) that will be used when |
|           | logging on to the WebSphere Application Server           |
|           | administrative console.                                  |        
<!-- endif -->
<!-- if (${zAdminSecurityType} != websphereForZos) -->
|           | complies with your institution standards.                |
<!-- endif -->
|           |                                                          |        
|           | Enter the following RACF command to assign a password:   |        
|           |                                                          |        
|           |   ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED   |
|           |                                                          |        
|           | Enter the following RACF command to assign a             |        
|           | password phrase:                                         |        
|           |                                                          |        
|           |   ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED    |
|           |                                                          |
|           | If you are using a different security system, make sure  |        
|           | that the ${zAdminUserid} user ID has a password or       |
|           | password phrase.                                         |
|           |                                                          |
|           | To use RACF password phrase support, your target system  |
|           | must be at z/OS Version 1.9 or above.                    |       
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBOSBRAK.                                                |        
|           |                                                          |        
|           | When this step is complete, all groups and user IDs      |        
|           | listed above for job BBOSBRAK should be defined in the   |        
|           | RACF database on each target system for the cell.        |        
|           | Note: the WAS administrator user ID ${zAdminUserid} MUST have |
|           | the WAS configuration group ${zConfigurationGroup} as its default |
|           | OMVS group.                                              |
+-----------+----------------------------------------------------------+        
| BBOSBRAM  | User ID requirement:                                     |        
+-----------+     File system update authority (see above).            |        
|           |                                                          |        
| Done:     | This job creates home directories for WebSphere for z/OS |        
|           | user IDS. These home directories will be subdirectories  |        
|           | of ${zUserIDHomeDirectory}                                            |        
| By:       |                                                          |        
|           | This job will:                                           |        
|           |                                                          |        
|           | Create the following directory with permission bits 755: |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}                                              |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zConfigurationGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zConfigurationGroup}                                     |       
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zLocalUserGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zLocalUserGroup}                                     |        
|           |                                                          |        
|           | This job should be run on each z/OS system that will     |        
|           | host WebSphere Application Server nodes using these      |        
|           | WebSphere for z/OS common groups and owner user ID.      |        
|           | After execution, verify that the directories have been   |        
|           | created with the correct permissions on each system.     |        
|           |                                                          |        
|           | If these directories already exist with the specified    |        
|           | ownership and permission on a target system, then this   |        
|           | job does not need to be run on that system.              |        
|           |                                                          |        
|           | ATTENTION: If the directory                              |        
|           |  ${zUserIDHomeDirectory}                                               |        
|           | is used by applications other than WebSphere Application |        
|           | Server, make sure that the permissions set by            |        
|           | BBOSBRAM (755) are appropriate, or change them manually. |        
|           | This directory must be world-readable for Websphere      |        
|           | Application Server to run correctly.                     |
+-----------+----------------------------------------------------------+        
| BBOMBRAK  | User ID requirement: RACF special authority.             |         
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create RACF users |
|           | and profiles required by this WebSphere for z/OS node.   |
| By:       |                                                          |
<!-- if (${zDaemonUserid}token != token) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
|           | The following user ID(s) will be created:                |
<!-- endif -->
<!-- if (${zDaemonUserid}token == token) -->
<!-- if (${zAdjunctUserid}token != token) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
|           | The following user ID(s) will be created:                |
<!-- endif -->
<!-- endif -->
<!-- if (${zDaemonUserid}token != token) -->
|           |  Daemon user ID:            ${zDaemonUserid} (uid ${zDaemonUid}) |
<!-- endif -->
<!-- if (${zAdjunctUserid}token != token) -->
|           |  Adjunct user ID:           ${zAdjunctUserid} (uid ${zAdjunctUid}) |
<!-- endif -->
|           |                                                          |        
|           | The commands are located in member BBOMBRAC of data set  |        
|           | ${zTargetHLQ}.DATA.                                      |        
|           |                                                          |
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBOMBRAK.                                                |
+-----------+----------------------------------------------------------+        
| BBOMSGC   | User ID requirement: Update authority for data set       |        
+-----------+ SYS1.MSGENU and/or SYS1.MSGJPN.                          |        
| Done:     |                                                          |        
|           | ATTENTION: This is optional unless you require message   |        
|           | translation.                                             |        
| By:       |                                                          |        
|           | This job sets up MMS to translate messages for WebSphere |        
|           | for z/OS.                                                |
|           |                                                          |
|           | Before running this job, update the INPUT DD statements  |
|           | to point to the SBBOMSG data set for your installation.  |
|           |                                                          |
|           | There are two steps to update: One that performs a copy  |
|           | to SYS1.MSGENU and one that performs a copy to           |
|           | SYS1.MSGJPN. Remove the unneeded step and if necessary,  |
|           | change the target libraries.                             |
+-----------+----------------------------------------------------------+        
|           | Check WebSphere Application Server home directories.     |        
+-----------+                                                          |        
| Done:     | Verify that the following directories exist on your      |        
|           | target z/OS system and that the ownership and permission |        
|           | bits are correct:                                        |        
| By:       |                                                          |        
|           | ${zUserIDHomeDirectory}                                               |        
|           | ownership: (any)                                         |        
|           | permission bits: 755                                     |        
|           |                                                          |        
|           | ${zUserIDHomeDirectory}/${zConfigurationGroup}                                      |        
|           | ownership: ${zControlUserid}:${zConfigurationGroup}                             |        
|           | permission bits: 770                                     |        
|           |                                                          |        
|           |                                                          |        
|           | ${zUserIDHomeDirectory}/${zServantGroup}                                      |        
|           | ownership: ${zControlUserid}:${zServantGroup}                             |        
|           | permission bits: 770                                     |        
|           |                                                          |        
|           |                                                          |        
|           | ${zUserIDHomeDirectory}/${zLocalUserGroup}                                      |        
|           | ownership: ${zControlUserid}:${zLocalUserGroup}                             |        
|           | permission bits: 770                                     |        
|           |                                                          |        
|           | If the these directories do not exist, create them with  |        
|           | the above ownership and permission bits.                 |        
|           |                                                          |        
|           | The security domain configuration job BBOSBRAM can be    |        
|           | used to create these directories if necessary.           |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | Check user ID authorizations.                            |        
+-----------+                                                          |        
| Done:     | Make sure the ${zConfigurationGroup} group has read access to all     |        
|           | WebSphere product data sets, as well as to any other     |        
|           | data sets which will be placed in WebSphere for z/OS     |        
|           | cataloged procedure STEPLIB concatenations.              |        
|           |                                                          |        
| By:       | the resolver configuration file in use on your system.   |        
|           | Depending on your IP setup, this file may be             |        
|           | /etc/resolv.conf, SYS1.TCPPARMS(TCPDATA), or another     |        
|           | data set.                                                |        
|           |                                                          |        
|           | ${zControlUserid}                                                 |        
|           | ${zServantUserid}                                                 |        
|           |                                                          |        
|           | See the z/OS eNetwork Communication Server IP            |        
|           | Configuration manual for the resolver search order.      |        
|           |                                                          |        
|           | Ensure the following user ID has read access to the data |        
|           | sets in your system parmlib concatenation:               |        
|           |                                                          |        
|           | ${zControlUserid}                                        |        
<!-- if (${zDaemonUserid}token != token) -->
<!-- if (${zDaemonUserid} != ${zControlUserid}) -->
|           | ${zDaemonUserid}                                         |        
<!-- endif -->
<!-- endif -->
|           |                                                          |        
|           | ATTENTION:                                               |        
|           |                                                          |        
|           |  If operator commands are protected by the z/OS security |        
|           |  server at your installation, you must ensure that       |        
|           |  sufficient authority is given to WebSphere tasks to     |        
|           |  control operations.                                     |        
|           |                                                          |        
|           |  The Application Server Controller user ID (${zControlUserid})     |        
|           |  needs the ability to perform operations on started      |        
|           |  tasks belonging to WebSphere Application Server for     |        
|           |  z/OS.                                                   |        
|           |                                                          |        
|           |  Any user ID that is used to run the federation job when |
|           |  the node agent is started automatically, needs the      |
|           |  authority to issue the MVS START command.                                  |        
|           |                                                          |        
|           |  If you are currently controlling MVS console command    |        
|           |  authority with SAF OPERCMDS profiles, grant the         |        
|           |  following authorities as indicated, substituting your   |        
|           |  own profile names:                                      |        
|           |                                                          |        
|           |  PERMIT  START_profile_name  CLASS(OPERCMDS)             |        
|           |          ID (${zControlUserid})  ACCESS(UPDATE)          |        
|           |                                                          |        
|           |  PERMIT  STOP_profile_name  CLASS(OPERCMDS)              |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)         |        
|           |                                                          |        
|           |  PERMIT  MODIFY_profile_name  CLASS(OPERCMDS)            |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)         |        
|           |                                                          |        
|           |  PERMIT  CANCEL_profile_name  CLASS(OPERCMDS)            |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)         |        
|           |                                                          |        
|           |  PERMIT  FORCE_profile_name  CLASS(OPERCMDS)             |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)         |        
|           |                                                          |        
|           |  You must also grant the appropriate console command     |        
|           |  authority to any user ID that executes the              |        
|           |  startServer.sh or stopServer.sh script.                 |        
|           |                                                          |
+-----------+----------------------------------------------------------+        
| BBOMCFS   | User ID requirement:                                     |        
+-----------+     File system update authority (see above), and the    |        
|           |     authority to allocate                                |        
|           |        ${zConfigHfsName}                                 |        
| Done:     |                                                          |        
|           | Before running this job:                                 |        
|           |                                                          |        
| By:       | Verify that the DD statement which defines the data set  |        
|           | is valid for the storage rules defined on the target     |        
|           | system.                                                  |        
|           |                                                          |        
|           |                                                          |        
|           | This job:                                                |        
|           |                                                          |        
|           | o   Creates a mount point directory                      |        
|           |                                                          |        
|           |     ${zConfigMountPoint}                                 |        
|           |                                                          |        
|           | o   Allocates the configuration file system              |
|           |                                                          |        
|           |     ${zConfigHfsName}                                    |        
|           |                                                          |        
|           |     and mounts it at the above mount point.              |        
|           |                                                          |
|           | Note: You can run job BBO855CN instead of BBOMCFS        |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855CN job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        | 
|           | BBO855CN and BBOMCFS jobs are the same.                  |
|           |                                                          |        
|           | DO NOT RUN THIS JOB IF:                                  |        
|           |   1. The configuration file system already exists and is |        
|           |      mounted at the desired mountpoint, or if            |        
|           |                                                          |        
|           |   2. The mount point directory is controlled by          |        
|           |      automount.  Either disable the automount rule for   |        
|           |      the configuration mount point while running this    |        
|           |      job, or perform the following steps manually:       |        
|           |                                                          |        
|           |      a. Allocate the configuration file system data set. |        
|           |      b. Issue the following shell commands, which will   |        
|           |         also cause automount to mount the file system    |        
|           |                                                          |        
|           |      chmod 775 ${zConfigMountPoint}                      |        
|           |                                                          |        
|           |      chown ${zAdminUserid}:${zConfigurationGroup}        |        
|           |        ${zConfigMountPoint}                              |        
|           |                                                          |        
|           | BEFORE YOU BEGIN: The BBOMCFS job assumes your root      |        
|           | file system is mounted in read/write mode.  If the root  |        
|           | file system is not mounted in read/write mode, manually  |        
|           | create the directory                                     |        
|           |                                                          |        
|           | ${zConfigMountPoint}                                     |        
|           |                                                          |        
|           | and any needed higher directories, set file permissions  |        
|           | to 775, and set the owning user ID and group to ${zAdminUserid}|        
|           | and ${zConfigurationGroup} before running BBOMCFS.       |        
|           |                                                          |        
|           | EXAMPLE: If you plan to use /wasv8config as your         |        
|           | directory, issue the following commands from within the  |        
|           | OMVS shell:                                              |        
|           |                                                          |        
|           |   mkdir -p -m 775 /wasv8config                           |        
|           |   chown -R ${zAdminUserid}:${zConfigurationGroup} /wasv8config|        
|           |                                                          |
+-----------+----------------------------------------------------------+        
| BBOMHFSA  | User ID requirement:                                     |        
+-----------+     File system update authority (see above).            |        
|           |                                                          |        
| Done:     | This job populates the previously-created configuration  |
|           | file system and prepares it for profile creation.        |        
| By:       |                                                          |
|           | Note: You can run job BBO855HN instead of BBOMHFSA       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855HN job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        | 
|           | BBO855HN and BBOMHFSA jobs are the same.                 |
|           |                                                          |        
|           | Note: If the SCEERUN data set is not in the system link  |        
|           | list, add that data set to STEPLIB for the CHECKV step   |        
|           | in BBOMHFSA.                                             |        
|           |                                                          |        
|           | Upon completion, examine the job output. Success is      |        
|           | indicated with a RC=0 in the job output.                 |        
|           |                                                          |        
+-----------+----------------------------------------------------------+                
| --------  | Verify the IBM SDK for Java selection.                   |        
+-----------+                                                          |        
|           | By default the WebSphere Application Server node will be |
| Done:     | configured to use the IBM SDK for Java 6 with 64-bit     |
|           | addressing. To configure with a different SDK enter the  |
| By:       | following commands:                                      |
|           |                                                          |
|           |   cd ${zConfigMountPoint}/                               |        
|           |    ${zWasServerDir}/bin                                  |        
|           |                                                          |
|           |   ./managesdk.sh -setNewProfileDefault -sdkName XXXXXX   |
|           |                                                          |
|           | where XXXXXX is set to one of the following values:      |
|           |                                                          |
|           |   1.6_31   (IBM SDK for Java 6 with 31-bit addressing)   |
|           |   1.6_64   (IBM SDK for Java 6 with 64-bit addressing)   |
|           |   1.7_31   (IBM SDK for Java 7 with 31-bit addressing)   |
|           |   1.7_64   (IBM SDK for Java 7 with 64-bit addressing)   | 
|           |   1.7.1_31 (IBM SDK for Java 7.1 with 31-bit addressing) |
|           |   1.7.1_64 (IBM SDK for Java 7.1 with 64-bit addressing) |
|           |                                                          |
|           | Note that you must have the IBM WebSphere SDK for        |
|           | Java(TM) Technology Edition Version 7.0 or 7.1           |
|           | installed to specify one of the Java 7 or 7.1 SDKs.      |
|           | Use the following commands to determine which SDKs       |
|           | are available:                                           |
|           |                                                          |
|           |   cd ${zConfigMountPoint}/                               |        
|           |    ${zWasServerDir}/bin                                  |        
|           |                                                          |
|           |   ./managesdk.sh -listAvailable                          |
|           |                                                          |
+-----------+----------------------------------------------------------+                
| BBOWWPFM  | User ID requirement:                                     |        
+-----------+     File system update authority (see above).            |        
|           |                                                          |        
| Done:     | This job creates a profile (set of configuration files   |
|           | for a node) in the configuration file system.            |        
| By:       |                                                          |
|           | Note: You can run job BBO855PN instead of BBOWWPFM       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855PN job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        | 
|           | BBO855PN and BBOWWPFM jobs are the same.                 |
|           |                                                          |        
|           | Note: If the SCEERUN2 data set is not in the system link |        
|           | list, add that data set to STEPLIB for the LIBVSCRP step |        
|           | in BBOWWPFM.                                             |        
|           |                                                          |        
|           | Upon completion, examine the job output. Success is      |        
|           | indicated by rc=0.                                       |        
|           |                                                          |        
|           | Note: If the BBOWWPFM (profile creation job) fails, you  |        
|           | must perform the following steps to remove the partially |        
|           | built profile:                                           |        
|           |                                                          |        
|           |   cd ${zConfigMountPoint}/                               |        
|           |    ${zWasServerDir}                                      |        
|           |                                                          |        
|           |   ./bin/manageprofiles.sh -deleteAll                     |        
|           |                                                          |        
|           |   rm -R profiles                                         |        
|           |                                                          |        
|           | Then, correct the problem that caused BBOWWPFM to fail   |        
|           | and re-run the job                                       |        
|           |                                                          |
+-----------+----------------------------------------------------------+   
| BBOMPROC  | User ID requirement:                                     |        
+-----------+     Authority to update the cataloged procedure library  |        
| Done:     |     ${zProclibName}                                      |
|           |                                                          |        
| By:       |                                                          |        
|           | This job creates the tailored cataloged procedures and   |        
|           | copies them to your procedure library.                   |        
|           |                                                          |
|           | Note: You can run job BBO855RN instead of BBOMPROC       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855RN job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        | 
|           | BBO855RN and BBOMPROC jobs are the same.                 |
|           |                                                          |        
|           | ATTENTION: Be aware that you may overlay existing        |        
|           | members in the above data set.                           |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | All WebSphere Application Server processes require       |        
+-----------+ access to the Language Environment and System SSL load   |        
| Done:     | modules.                                                 |        
|           |                                                          |        
| By:       | If the SCEERUN, SCEERUN2 and System SSL load module      |        
|           | libraries are not in the system link list, add them to   |        
|           | the STEPLIB DD concatenation in each of the following    |        
|           | cataloged procedures in                                  |        
|           | ${zProclibName}:                                         |        
|           |                                                          |        
|           |     ${zControlProcName}                                  |        
|           |     ${zServantProcName}                                  |        
|           |     ${zAdjunctProcName}                                  |        
|           |     ${zDaemonProcName}                                   |        
|           |                                                          |        
|           | and also add the full data set names, separated by       |        
|           | colons (:), to the STEPLIB variable in the shell script  |       
|           |                                                          |        
|           |     ${zConfigMountPoint}/                                |        
|           |      ${zWasServerDir}/                                   |        
|           |       profiles/default/bin/setupCmdLine.sh               |        
|           |                                                          |        
|           | When modifying the setupCmdLine.sh script, do not        |        
|           | remove lines or comment them out, as this may cause      |        
|           | problems with automated updates to the script.           |        
|           |                                                          |        
|           | Add only those data sets which are NOT in the link list. |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | Make sure Resource Recovery Services (RRS) is active.    |        
+-----------+ (See the online information center for setup             |        
| Done:     | instructions if necessary.) Look for the following       |
|           | console message to verify that RRS was successfully      |        
|           | started:                                                 |        
|           |                                                          |        
| By:       |                                                          |        
|           |   ASA2011I RRS INITIALIZATION COMPLETE. COMPONENT        |        
|           |     ID=SCRRS                                             |        
|           |                                                          |        
<!-- if (${zFederateDmaSecurity} == true) -->
<!-- if (${zAdminSecurityType} == websphereFamily) -->
+-----------+----------------------------------------------------------+        
| --------- | If both your target Network Deployment cell and the cell |        
+-----------+ containing the node you are federating use WebSphere-    |        
|           | managed security, and both cells are using file-based    |        
| Done:     | keystores, run the retrieveSigners.sh script from the    |        
|           | home directory of the node being federated:              |        
|           |                                                          |        
|           | ${zConfigMountPoint}                                     |        
| By:       |  /${zWasServerDir}                                       |        
|           |  /bin/retrieveSigners.sh CellDefaultTrustStore           |        
|           |  ClientDefaultTrustStore -port ${zFederateDmaPort}       |        
|           |  -conntype ${zFederateDmaPortType}                       |        
|           |  -user ${zFederateDmaSecurityUserID}                     |        
|           |  -password ${zFederateDmaSecurityPassword}               |        
|           |  -autoAcceptBootstrapSigner                              |
<!-- endif -->
<!-- endif -->
<!-- if (${zFederateDmaSecurity} == false) -->
+-----------+----------------------------------------------------------+        
| ----------|                                                          |        
+-----------+ Verify that your target Network Deployment cell is       |        
| Done:     | running without administrative security.  You should     |        
|           | enable administrative security after federation to       |        
| By:       | prevent unauthorized access to the Network Deployment    |        
|           | cell.                                                    |        
|           |                                                          |        
<!-- endif -->
+-----------+----------------------------------------------------------+        
| BBOWMNAN  | User ID requirement:                                     |        
+-----------+  1. File system update authority (see above).            |        
|           |  2. If the Network Deployment cell uses a z/OS LocalOS   |        
| Done:     |     (SAF) registry, then the user ID used to run this    |        
|           |     job must be connected to the Network Deployment      |        
|           |     cell's configuration group.                          |        
| By:       |  3. If SSL certificates are stored in SAF keyrings,      |        
|           |     then the user ID used to run this job must have a    |        
|           |     SAF keyring named the same as the one that was used  |
|           |     when the managed node was created.  That keyring     |
|           |     must contain the Network Deployment cell's CA        |
|           |     certificate.  Refer to the the contents or output of |
|           |     the BBOMBRAC job, or the zDefaultSAFKeyringName      |
|           |     variable in your zPMT response file, for the name of |
|           |     that keyring.                                        |
|           |                                                          |       
|           | If you choose to start the node agent automatically,     |        
|           | the user ID used to run BBOWMNAN will also need the      |        
|           | authority to issue the MVS START command.                |        
|           |                                                          |        
|           | This job will federate your node into the specified      |        
|           | Network Deployment cell.  Ensure that the cell's         |        
|           | Deployment Manager is running before submitting this job.|        
|           |                                                          |
|           | Note: You can run job BBO855UN instead of BBOWMNAN       |
|           | if the target WebSphere Application Server for z/OS      |
|           | installation image is at least at the 8.5.5.0 service    |
|           | level. The BBO855UN job will use the directory specified |
|           | by the TMPDIR environment variable, if defined, for      |
|           | temporary files. The user ID requirements for the        | 
|           | BBO855UN and BBOWMNAN jobs are the same.                 |
|           |                                                          |        
|           | Upon completion, examine the job output. Success is      |        
|           | indicated with a RC=0 in the job output.                 |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | If your system is busy, you may want to include a rule   |        
+-----------+ in your WLM policy that OMVS work for job ${zFederateServerShortName}     |        
| Done:     | (such as the postinstaller step) is to run in a service  |        
|           | class with a high service objective.                     |        
| By:       |                                                          |        
+----------------------------------------------------------------------+        
| --------  | Start the node agent server                              |        
+-----------+                                                          |        
| Done:     | Note: The node agent may have been started during the    |        
|           | federation process.                                      |        
|           |                                                          |        
| By:       | Issue the following MVS command to start your node agent |        
|           | server, replacing <dmgr_cell_short_name> with the cell   |        
|           | short name of the target Deployment Manager cell         |        
|           |                                                          |        
|           |   START ${zControlProcName},JOBNAME=${zFederateServerShortName},                      |        
|           |    ENV=<dmgr_cell_short_name>.${zNodeShortName}.${zFederateServerShortName}         |
|           |                                                          |        
|           |                                                          |        
|           | RESULT: The following message appears on the console and |        
|           | in the job log of ${zFederateServerShortName}.                            |        
|           |                                                          |        
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |        
|           |   z/OS CONTROL PROCESS ${zFederateServerShortName}                        |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| The product is now configured.  You may create and manage            |        
| application servers in the node using the administrative console or  |        
| scripting.                                                           |
|                                                                      |
| To run your created server in a reusable address space, add          |
| ",REUSASID=YES" to the end of its START command. See the article     |
| "Reusable address space" in the WebSphere Application Server for z/OS|
| Information Center for more information, and important restrictions. |
+----------------------------------------------------------------------+
