<!-- ================================================================ -->         
<!-- PROPRIETARY-STATEMENT:                                           -->         
<!-- Licensed Material - Property of IBM                              -->         
<!--                                                                  -->         
<!-- 5724-I63, 5724-H88, 5655-N01, 5733-W61                           -->         
<!-- (C) Copyright IBM Corp. 2005, 2012                               -->         
<!-- All Rights Reserved                                              -->         
<!-- US Government Users Restricted Rights - Use, duplication or      -->         
<!-- disclosure restricted by GSA ADP Schedule Contract with IBM Corp.-->         
<!-- ================================================================ -->         
<!--                                                                  -->         
<!-- Common augmentation response file                                -->         
<!--                                                                  -->         
<!-- Change Activity:                                                 -->         
<!--                                                                  -->         
<!--  PM61388       V7.0  20120629  PDOP: Initial version             -->
<!-- ================================================================ -->  

<!-- if (${zAdminSecurityType} == websphereFamily) -->
                                                                           
/* ---------------------------------------------------------------- */
/* Activates CBIND class.                                           */
/* ---------------------------------------------------------------- */
say 'Activating CBIND class. '
"SETROPTS RACLIST(CBIND) GENERIC(CBIND)"
say

/* --------------------------------------------------------------------- */
/* CLASS=CBIND                                                           */
/* OS/390 WebSphere PROFILES                                             */
/* --------------------------------------------------------------------- */
/*  CLASS  = CBIND                                                       */
/* PROFILE = CB.BIND.<cluster name>                                      */
/*  (CB.BIND.CLUSTER)                                                    */
/* Used for: determining if a client can "BIND" (access) a controller    */
/*           region.                                                     */
/* Notes:                                                                */
/* 1. Any userid can gain access to the controller region if it has READ */
/*    access to the CB.BIND.cluster_name profile.                        */
/* 2. A userid can still gain access to the Controller Region if the     */
/*    session owner has control access.                                  */
/* 3. Within a local session (or SSL client certificate session)         */
/*    the session owner is the userid of the client or controller        */
/*    region (if server-as-client) that issued the message.              */
/*    Otherwise, ownership is assigned to the first userid which         */
/*    has successfully accessed the controller region.                   */
/* --------------------------------------------------------------------- */
say 'Define and permit CB.BIND.<cluster name> profile to CBIND class'
say 'Used for determining if a client can access a controller region'
say 'Any userid can gain access to the controller region if it has READ access to the CB.BIND.cluster_name profile'
"RDEFINE CBIND CB.BIND.** UACC(READ)"
"PERMIT CB.BIND.** CLASS(CBIND) ID(${zConfigurationGroup}) ACCESS(CONTROL)"
say

/* ---------------------------------------------------------------- */
/* ACCESS TO J2EE Applications                                      */
/* ---------------------------------------------------------------- */
/* CLASS  = CBIND                                                   */
/* PROFILE = CB.<CLUSTER NAME>                                      */
/* Used for: Determining if a client can use J2EE applications in a */
/*           server.                                                */
/* ---------------------------------------------------------------- */
say 'Define and permit CB.<cluster name> profile to CBIND class'
say 'Used for determining if a client can use J2EE applications in a server'
"RDEFINE CBIND CB.** UACC(READ)" 
say
"SETROPTS RACLIST(CBIND) GENERIC(CBIND) REFRESH"
say
<!-- endif -->
