<!-- ================================================================ -->         
<!-- PROPRIETARY-STATEMENT:                                           -->         
<!-- Licensed Material - Property of IBM                              -->         
<!--                                                                  -->         
<!-- 5724-I63, 5724-H88, 5655-N01, 5733-W61                           -->         
<!-- (C) Copyright IBM Corp. 1999, 2008                               -->         
<!-- All Rights Reserved                                              -->         
<!-- US Government Users Restricted Rights - Use, duplication or      -->         
<!-- disclosure restricted by GSA ADP Schedule Contract with IBM Corp.-->         
<!-- ================================================================ -->         
<!--                                                                  -->         
<!-- Change Activity:                                                 -->         
<!--                                                                  -->         
<!--   LIDB3773-25 V6.1 110305  PDOP: Initial version                 -->
<!--   320449      V6.1 110705  PDOP: Port updates                    --> 
<!--   324527      V6.1 111605    DB: Updates to cell instructions    -->
<!--   325782      V6.1 112205    DB: change BBORTSS5 to BBORTS61     -->
<!--   328482      V6.1 120105    DB: rename bbowcpyc to bboccpy1,    -->
<!--                                  rename bbodchfs to bbocchfs     -->
<!--   330776  H28W610 121405    DB: update instructions based on     -->         
<!--                                 change to SBBOLPA/SBBOLOAD       -->
<!--   337027     V6.1  011206   DB: Remove excess period             -->
<!--   337854  H28W610 011206    DB: fix some typos                   -->
<!--   333384  H28W610 011306    DB: add zfs support                  -->
<!--  333384.1 H28W610 011906    DB: filesystem should be two words   -->                  
<!--  337515   H28W610 012306    DB: updates for STEPLIB changes      -->
<!--  342401   H28W610 013006    DB: change FILEZFS to FSTYPE         -->  
<!--  342461   H28W610 013106    DB: update OPERCMDs instructions     --> 
<!--  354688   H28W610 031406    DB: LE/SSL datasets don't go in LPA  -->
<!--  356728   H28W610 032406    DB: updates for two file systems     --> 
<!--  358147   H28W610 032706    DB: add IPv6 Node multicast port     -->
<!--  360936   H28W610 040606    DB: fix a typo                       -->
<!-- PK20049   H28W610 042206    DB: instructions for LE in STEPLIB   -->
<!-- 364931    H28W610 042406    DB: updates for non root install     -->
<!--  373993   H28W610 082206    DB: SAF profile update for zFS       -->
<!-- 367833    H28W610 082306    DB: BBOCBRAJ section refers to wrong -->
<!--                                 member                           -->
<!--  370154   H28W610 083106    DB: Add verify stmt for HFS jobs     -->
<!--  390937   H28W610 100206    DB: 64-bit instruction changes       -->
<!--  396347   H28W610 100806    DB: Additions for asterisk id        -->
<!--  396571   H28W610 101106    DB: Add text for AUTOMOVE            -->
<!--  402402   H28W610 110106    DB: Reword AUTOMOVE text             -->
<!--  411108   H28W610 121206    DB: Fix possible length error        -->         
<!--  412596   H28W610 010307    DB: Add SBBGLOAD references          -->
<!--  412597   H28W610 010807    DB: fix minor text issues            -->                     
<!--  396079.1 H28W610 011507  PDOP: App server data sets for cell    -->
<!-- LIDB4489-16 H28W700 040107  DB: 64-bit updates                   -->
<!--  429965   H28W700 040207  PDOP: Fix length error                 -->
<!--  425357   H28W610 040907    DB: use aggrgrow option for ZFS      -->
<!--  447303   V7.0    070614  PDOP: Userid simplification            -->
<!--  447258   V7.0    062607  PXTN: Convert zmpt variables.          -->
<!--  465452   V7.0    101907  PDOP: Updated profile cleanup info     -->
<!--  LIDB4689  V7.0    20071024 DMB: Move load modules to hfs        -->
<!--  466649   V7.0    102507  PDOP: Remove refs to config dialog     -->
<!--  484621   V7.0    112807  PDOP: Updated "Z" proclib references   -->
<!--   489808  V7.0    122007   PXT: Change order of BBOCCPY1 to run  -->
<!--  492063   V7.0    011507   DMB: Use one step RACF jobs           -->
<!--  502633   V7.0    030308  PDOP: Removed use of "InfoCenter"      -->
<!--  504724   V7.0    031808  PDOP: Added prod file system directions-->
<!--   500745  V7.0    20080407 PXT: Change the order of DD statement -->
<!--511429.1 V7.0   20080519   DMB: Create SR id in bbosbrac          -->
<!--  538461   V7.0   20080723 PDOP: Add SCLBDLL2 to system link list -->
<!--  567032   V7.0   20081203 PDOP: Clean up                         -->
<!--  PK70886  V7.0   20081216  DMB: Add region size warning info     -->
<!--  567032.1 V7.0   20090116 PDOP: Additional clean up              -->
<!-- PK83899   V7.0   20090413 DMB: Update section on SCHEDxx member  -->
<!-- PK94663  V7.0     20090922  DMB: Update BBOMSGC step             -->
<!-- PM12309  V7.0    20100721 DMB: Updates for REUSASID              -->
<!--  715560   V8.0   20110908 PDOP: Show WAS version                 -->
<!--  745081   V7.0   20130306 PDOP: Update SAF profile privileges    -->         
<!-- ================================================================ -->         
                                                                                                                                                                                                                                        
-----------------------------------------------                                 
WebSphere Application Server for z/OS V7.0 customization instructions:

Deployment manager ${zServerShortName}  (cell ${zCellShortName}, node ${zNodeShortName})  
Federated application server ${zAppServerServerShortName}  (node ${zAppServerNodeShortName})  
Tailored on ${ZDATE} at ${ZTIMEL} by ${ZUSER}
WCT version ${wctVersion} build ${wctBuild} 
                                                                                                                                                                                                                                        
The customization tools have created jobs based on the information you          
provided. These instructions tell you how to modify the operating               
system and run the jobs to customize WebSphere for z/OS.                        
                                                                                
                                                                                                                                                               
RULES:                                                                          
                                                                                                                                                                                                                                       
1.  If you created the target data sets (*.CNTL and *.DATA) on another          
    (driving) system, you must copy them to the target system and give          
    them the same data set names.                                                                                                                         
                                                                                
2.  You must perform these instructions on your target system.                  
                                                                                                                                                               
Doing manual configuration updates                                              
                                                                                
----------------------------------                                              
                                                                                                                                                                
You must perform the following manual steps on the target z/OS system 
before running the WebSphere for z/OS configuration jobs.  
                                                                                                                                                        
1.  Update BLSCUSER. Refer to member BBOIPCSP in                                
                                                                        
    ${zTargetHLQ}.CNTL
                                                                          
    In order to use the IPCS support provided by the product, append            
    the contents of this member to the BLSCUSER member in your IPCSPARM         
    or system PARMLIB datasets.                                                 
                                                                                                                                                                
    -------------------------------------------------------------------         
                                                                          
2.  Update SCHEDxx. Refer to member BBOSCHED in                                 
                                                                          
    ${zTargetHLQ}.CNTL                                                                   
                                                                         
    In order to set the correct program properties for the WebSphere            
    for z/OS run-time executables, append the contents of this member           
    to the SCHEDxx member in your system PARMLIB concatenation.                 
                                                                          
    Note: When you are finished, issue the command SET SCH=xx to
	activate SCHEDxx and load a new program properties table.  This
	action does not need to be performed if the target z/OS system is
	at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED
	member contains already exists in the IBM-supplied PPT table at
	those z/OS levels.                
                                                                                                                                                         
    -------------------------------------------------------------------

3.  If you want to collect the SMF120 records created by the run-time           
    servers, update SMFPRMxx via the following:                                 
                                                                                                                                                                                                                                                            
    EXAMPLE:                                                                    
                                                                                                                                                                                                                                     
       SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),                    
                          TYPE(0,30,70:79,88,89,120,245))                       
                                                ---                             
                                                                          
    For details on the SMF records, see related topics in the                   
    WebSphere for z/OS Information Center at                                    
    http://www.ibm.com/software/webservers/appserv/zos_os390/library/           
                                                                                                                                                                                                                                       
    -------------------------------------------------------------------         
                                                                                                                                                          
<!-- import documents/cntl/cellDMgrProductFileSystem.txt -->
                                                                                
    -------------------------------------------------------------------         
                                                                                                                                                          
<!-- import documents/cntl/cellAppServerProductFileSystem.txt -->
                                                                                
    -------------------------------------------------------------------         
                                                                          
6.  Update your active BPXPRMxx member to have the following WebSphere          
    for z/OS configuration file systems:                                                 
                                                                          
    ${zConfigHfsName}

    and                                                                   

    ${zAppServerConfigHfsName}
                                                                         
    mounted at:                                                                 
                                                                          
    ${zConfigMountPoint}

    and

    ${zAppServerConfigMountPoint}                                                                  
                                                                          
    in read/write mode.                                                         
                                                                                                                                                      
                                                                                                                                                                                                                                     
    EXAMPLE:                                                                    
                                                                                                                                                         
<!-- if (${zFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR) PARM('AGGRGROW')
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR)
<!-- endif -->
                                                                                
<!-- if (${zAppServerFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zAppServerConfigHfsName}')                                            
         MOUNTPOINT('${zAppServerConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR) PARM('AGGRGROW')
<!-- endif -->
<!-- if (${zAppServerFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zAppServerConfigHfsName}')                                            
         MOUNTPOINT('${zAppServerConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR)
<!-- endif -->

    If you are configuring in a sysplex environment, you may wish to
    add the NOAUTOMOVE parameter as follows:

<!-- if (${zFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR) PARM('AGGRGROW') SYSNAME(${zSystemName}) NOAUTOMOVE                                                                                 
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR) SYSNAME(${zSystemName}) NOAUTOMOVE
<!-- endif -->
                                                                                
<!-- if (${zAppServerFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zAppServerConfigHfsName}')                                            
         MOUNTPOINT('${zAppServerConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR) PARM('AGGRGROW') SYSNAME(${zSystemName}) NOAUTOMOVE
<!-- endif -->
<!-- if (${zAppServerFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zAppServerConfigHfsName}')                                            
         MOUNTPOINT('${zAppServerConfigMountPoint}')                                                                                                              
          TYPE(${zFilesystemType})                                                                                                                                    
          MODE(RDWR) SYSNAME(${zSystemName}) NOAUTOMOVE
<!-- endif -->

    The NOAUTOMOVE parameter in the examples above prevents the      
    configuration file system from being mounted on a different z/OS
    system in a shared file system configuration, which could cause 
    performance problems.                                                            
                                                                                
<!-- if (${zFilesystemType} == ZFS) -->
   If you have specified "aggrgrow=on" in your IOEFSPRM parmlib member,
   you can omit the AGGRGROW parm shown in the above examples
<!-- endif -->
<!-- if (${zAppServerFilesystemType} == ZFS) -->
<!-- if (${zFilesystemType} == HFS) -->
   If you have specified "aggrgrow=on" in your IOEFSPRM parmlib member,  
   you can omit the AGGRGROW parm shown in the above examples
<!-- endif -->
<!-- endif -->

    -------------------------------------------------------------------         
                                                                                                                                                        
7.  Update TCP/IP by reserving the following ports for WebSphere for            
    z/OS:                                                                       
                                                                                                                                                         
       Deployment manager ports 
                                                                               
          SOAP JMX Connector port                             - ${zSoapPort}               
          Cell Discovery Address port                         - ${zCellDiscoveryPort}               
          ORB port                                            - ${zOrbListenerPort}              
<!-- if (${zOrbListenerSslPort} != 0) -->
          ORB SSL port                                        - ${zOrbListenerSslPort}              
<!-- endif -->
          Administrative console port                         - ${zAdminConsolePort}               
          Administrative console secure port                  - ${zAdminConsoleSecurePort}              
                                                                        
          Administrative local port                           - ${zAdminLocalPort}                                                                   
          High Availability Manager Communications port       - ${zHighAvailManagerPort}             

       Node agent ports
      
          SOAP JMX Connector port                             - ${zNodeAgentJmxSoapConnectorPort}                 
          Node Discovery port                                 - ${zNodeAgentNodeDiscoveryPort}               
          Node Multicast Discovery Port                       - ${zNodeAgentNodeMulticastDiscoveryPort}               
          Node IPv6 multicast discovery port                  - ${zNodeAgentNodeIPv6MulticastDiscoveryPort}                
          ORB port                                            - ${zNodeAgentOrbPortName}                 
          Administrative local port                           - ${zNodeAgentAdminLocalPort}                                                                   
          High Availability Manager Communication port        - ${zNodeAgentHamCommPort}              
<!-- if (${zNodeAgentOrbSslPortName} != 0) -->
          ORB SSL port                                        - ${zNodeAgentOrbSslPortName}                
<!-- endif -->
       
       Application server ports
      
          SOAP JMX Connector port                             - ${zAppServerSoapPort}          
          ORB port                                            - ${zAppServerOrbListenerPort}          
<!-- if (${zOrbListenerSslPort} != 0) -->
          ORB SSL port                                        - ${zAppServerOrbListenerSslPort}       
<!-- endif -->
                                                                          
          Administrative local port                           - ${zAppServerAdminLocalPort}                                                                   
          High availability manager communication port        - ${zAppServerHighAvailManagerPort}        
          Service Integration port                            - ${zAppServerServiceIntegrationPort}          
          Service Integration Secure port                     - ${zAppServerServiceIntegrationSecurePort}         
          Service Integration MQ Interoperability port        - ${zAppServerServiceIntegrationMqPort}           
          Service Integration MQ Interoperability Secure port - ${zAppServerServiceIntegrationSecureMqPort}         
          Session Initiation Protocol (SIP) port              - ${zAppServerSessionInitiationPort}       
          Session Initiation Protocol (SIP) secure port       - ${zAppServerSessionInitiationSecurePort}         
    
       Daemon ports
                                                                               
          Daemon IP port                                      - ${zDaemonPort}              
          Daemon SSL port                                     - ${zDaemonSslPort}            
                                                                                                                                                                                                                                        
    View member BBOTCPIC in                                                                                                                               
                                                                                
    ${zTargetHLQ}.CNTL                                                                   
                                                                         
<!-- start of changed text for TCPDD                                               -->
                                                                                
    Add the contents of this member to the PORT section of the file             
    referenced by the DD statement for the TCP/IP profile in the                
    TCP/IP start procedure. Cut and paste from this member into the             
    data set used by your installation.                                         
                                                                                
<!-- end of changed text for TCPDD                                                 -->
                                                                                                                                                          
    ATTENTION: If another application has already reserved any of these         
    ports for its own use, you must resolve the resulting conflict              
    before you continue. Do not manually update the customization jobs
    and data files; instead, use the customization tools to regenerate      
    the customization jobs, data, and instructions.                    
                                                                        
    Note:  It is recommended that the IPCONFIG, UDPCONFIG, and                  
    TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to             
    only allow super users or APF-authorized user applications to bind          
    to privileged ports (1-1024), unless the SAF keyword is specified           
    and the user ID binding to the port is permitted to the SAF                 
    resource.  It is left up to the users' discretion to determine              
    whether this is a viable course of action given the users' specific         
    application/port requirements.                                             
                                                                        
    For more information please consult:                                        
                                                                         
    z/OS Communication Server IP Configuration Guide           
                                                                                                                       
    -------------------------------------------------------------------         
                                                                          
8.  WebSphere for z/OS customization assumes that the following system          
    data sets are in the system link list:                    
                                                                          
    Language Environment     SCEERUN                                            
                             SCEERUN2                                           
                                                                         
    System SSL               SIEALNKE
    
    Support for 64-bit       SCLBDLL2
                                                                         
    See the Language Environment Customization manual and the System            
    SSL Programming manual for your z/OS release for advice on placing          
    members from the libraries into the system link pack area.                  
                                                                       
    Placing these data sets in the link list insulates your WebSphere           
    for z/OS configuration from changes in data set names (for example,         
    when migrating to newer releases of z/OS).                                                
                                                                        
    If the Language Environment or System SSL load module libraries are         
    not in your system link list, you must perform the following steps          
    before starting any WebSphere Application Server for z/OS servers:          
                                                                         
    - Make sure the data sets are APF-authorized                                
    - Complete the optional step below to add the data sets to STEPLIB          
      in the server JCL and setupCmdLine.sh script(s).                          
                                                                        
    If you regenerate server cataloged procedures at any point, make            
    sure the data sets are added to the new cataloged procedures.
                                                                          
    -------------------------------------------------------------------         
                                                                                                                                                                                                                                        
Running the customized jobs                                                     
                                                                                
---------------------------                                                     
                                                                                                                                                                                                                                       
The customization tools built a number of batch jobs with the                  
information you supplied. You must run the jobs in the order listed               
below using user IDs with the appropriate authority.

<!-- import documents/cntl/fileSysUpdateAuth.txt -->
                                                                                
BEFORE YOU BEGIN: Complete the section above entitled "Doing manual             
configuration updates".                                                         
                                                                                                                                                         
                                                                                
Follow the table below, which lists in order the jobs you must submit           
and the commands you must enter. Special handling notes are included            
in the table. All jobs are members of                                           
                                                                                                                                                                                                                                        
${zTargetHLQ}.CNTL

By default, the customization jobs below are generated with REGION=0M.  
If this is not an allowable value on your target system, you may need to
modify this value for your environment.  Your system must allow a       
private region of sufficient size to allow the running of a Java Virtual
Machine Region with a maximum heap specification of 256 Megabytes       
(i.e., -Xmx256m).  Installation constraints that limit the region size  
or system exits that restrict the region a job is running in, may cause 
the customization jobs to fail due to a JVM error.  In the event of an  
Out of Memory (OOM) failure due to inadequate native storage, you must    
remove this constraint in order to successfully install WebSphere for   
z/OS.                                                                   
                                                                                                                                                                                                                                     
Attention: After submitting each job, carefully check the output.               
Errors may exist even when all return codes are zero.                           
                                                                                                                                                          
+-----------+----------------------------------------------------------+        
|           | The BBOSBRAK and BBOSBRAM jobs do not need to be run if  |
|           | the indicated groups, user IDs and directories already   |
|           | exist with the correct gid, uid and ownership permission |
|           | values, as given below.                                  |        
|           |                                                          |
|           | In order for RACF to automatically select an unused UID  |        
|           | or GID value for WebSphere Application Server user IDs   |        
|           | and groups:                                              |        
|           |                                                          |        
|           | - The RACF profile SHARED.IDS must be defined.           |        
|           | - The RACF profile BPX.NEXT.USER must be define and used |        
|           |   to indicate the ranges from which UID and GID values   |        
|           |   are to be selected.                                    |        
|           |                                                          |        
|           | See the article "Preparing the Security Server (RACF)"   |        
|           | in the WebSphere Application Server for z/OS online      |        
|           | information center. For more information, consult        |        
|           | Chapter 20, "RACF and z/OS Unix", in the z/OS Security   |        
|           | Server RACF Security Administrator's Guide (SA22-7683).  |                
+-----------+----------------------------------------------------------+        
| BBOSBRAK  |  User ID requirement: RACF special authority.            |        
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create common     |
|           | WebSphere for z/OS groups and user IDs                   |
| By:       |                                                          |
|           | Note: A uid or gid value of * indicates that the OS      |        
|           | security system is to select an unused UID or GID value  |        
|           |                                                          |
|           |  Administrator user ID:     ${zAdminUserid} (uid ${zAdminUid})      |
|           |  Control user ID:           ${zControlUserid} (uid ${zControlUid})      |
|           |  Servant user ID:           ${zServantUserid} (uid ${zServantUid}) |        
|           |  Configuration group:       ${zConfigurationGroup} (gid ${zConfigurationGroupGID})      |        
|           |  Servant group:             ${zServantGroup} (gid ${zServantGroupGID})      |        
|           |  Local user group:          ${zLocalUserGroup} (gid ${zLocalUserGroupGID})      |        
|           |                                                          |        
|           | The commands are located in member BBOSBRAC of data set  |        
|           | ${zTargetHLQ}.DATA.                                      |        
|           |                                                          |        
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | This job creates the WebSphere administrator ID ${zAdminUserid}|        
|           | without a password (or password phrase).  You must       |
|           | assign this user ID a password (or password phrase) that |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           | complies with your institution standards. This is also   |
|           | the password (or password phrase) that will be used when |
|           | logging on to the WebSphere Application Server           |
|           | administrative console.                                  |        
<!-- endif -->
<!-- if (${zAdminSecurityType} != websphereForZos) -->
|           | complies with your institution standards.                |
<!-- endif -->
|           |                                                          |        
|           | Enter the following RACF command to assign a password:   |        
|           |                                                          |        
|           |   ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED   |
|           |                                                          |        
|           | Enter the following RACF command to assign a             |        
|           | password phrase:                                         |        
|           |                                                          |        
|           |   ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED    |
|           |                                                          |
|           | If you are using a different security system, make sure  |        
|           | that the ${zAdminUserid} user ID has a password or       |
|           | password phrase.                                         |
|           |                                                          |
|           | To use RACF password phrase support, your target system  |
|           | must be at z/OS Version 1.9 or above.                    |       
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBOSBRAK.                                                |        
|           |                                                          |        
|           | When this step is complete, all groups and user IDs      |        
|           | listed above for job BBOSBRAK should be defined in the   |        
|           | RACF database on each target system for the cell.        |        
|           | Note: the WAS administrator user ID ${zAdminUserid} MUST have |
|           | the WAS configuration group ${zConfigurationGroup} as its default |
|           | OMVS group.                                              |
+-----------+----------------------------------------------------------+               
| BBOSBRAM  | User ID requirement:                                     |
+-----------+     File system update authority (see above).            |
|           |                                                          |       
| Done:     | This job creates home directories for WebSphere for z/OS |        
|           | user IDS. These home directories will be subdirectories  |        
|           | of ${zUserIDHomeDirectory}                                           |        
| By:       |                                                          |        
|           | This job will:                                           |        
|           |                                                          |        
|           | Create the following directory with permission bits 755: |
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}                                             |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zConfigurationGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zConfigurationGroup}                                     |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zServantGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zServantGroup}                                     |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zLocalUserGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zLocalUserGroup}                                     |        
|           |                                                          |        
|           | This job should be run on each z/OS system that will     |        
|           | host WebSphere Application Server nodes using these      |        
|           | WebSphere for z/OS common groups and owner user ID.      |        
|           | After execution, verify that the directories have been   |        
|           | created with the correct permissions on each system.     |        
|           |                                                          |        
|           | If these directories already exist with the specified    |        
|           | ownership and permission on a target system, then this   |        
|           | job does not need to be run on that system.              |        
|           |                                                          |    
+-----------+----------------------------------------------------------+        
| BBODBRAK  | User ID requirement: RACF special authority.             |         
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create RACF users |
|           | and profiles required by this WebSphere for z/OS cell.   |
|           | These commands are located in member BBODBRAC of data    | 
|           | set:                                                     |       
| By:       |                                                          |
|           | ${zTargetHLQ}.DATA                                       |
|           |                                                          |
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBODBRAK.                                                |        
+-----------+----------------------------------------------------------+        
| BBOCBRAK  | User ID requirement: RACF special authority.             |         
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create RACF users |
|           | and profiles required by this WebSphere for z/OS cell.   |
|           |                                                          |
|           | Note: A uid value of * indicates that the OS security    |
| By:       | system is to select an unused UID value.                 |
|           |                                                          |
|           | The following user ID(s) will be created:                |
|           |  Asynch admin user ID:      ${zAdminAsynchTaskUserid} (uid ${zAdminAsynchTaskUid}) |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           |  Unauthenticated user ID:   ${zAdminUnauthenticatedUserid} (uid ${zAdminUnauthenticatedUid}) |
<!-- endif -->
<!-- if (${zDaemonUserid}token != token) -->
|           |  Daemon user ID:            ${zDaemonUserid} (uid ${zDaemonUid}) |
<!-- endif -->
<!-- if (${zAdjunctUserid}token != token) -->
|           |  Adjunct user ID:           ${zAdjunctUserid} (uid ${zAdjunctUid}) |
<!-- endif -->
|           |                                                          |        
|           | These commands are located in member BBOWBRAC of data    | 
|           | set:                                                     |       
|           |                                                          |
|           | ${zTargetHLQ}.DATA                                       |
|           |                                                          |
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBOCBRAK.                                                |        
+-----------+----------------------------------------------------------+        
| BBOMSGC   | User ID requirement: Update authority for data set       |        
+-----------+ SYS1.MSGENU and/or SYS1.MSGJPN.                          |        
| Done:     |                                                          |        
|           | ATTENTION: This is optional unless you require message   |        
|           | translation.                                             |        
| By:       |                                                          |        
|           | This job sets up MMS to translate messages for WebSphere |        
|           | for z/OS.                                                |
|           |                                                          |
|           | Before running this job, update the INPUT DD statements  |
|           | to point to the SBBOMSG data set for your installation.  |
|           |                                                          |
|           | There are two steps to update: One that performs a copy  |
|           | to SYS1.MSGENU and one that performs a copy to           |
|           | SYS1.MSGJPN. Remove the unneeded step and if necessary,  |
|           | change the target libraries.                             |
+-----------+----------------------------------------------------------+        
| --------  | Check user ID authorizations.                            |        
+-----------+                                                          |        
| Done:     | Make sure the ${zConfigurationGroup} group has read access to all     |        
|           | WebSphere product data sets, as well as to any other     |        
|           | data sets which will be placed in WebSphere for z/OS     |        
|           | cataloged procedure STEPLIB concatenations.              |        
|           |                                                          |        
|           | Make sure the following user IDs have read access to     |        
| By:       | the resolver configuration file in use on your system.   |        
|           | Depending on your IP setup, this file may be             |        
|           | /etc/resolv.conf, SYS1.TCPPARMS(TCPDATA), or another     |        
|           | data set.                                                |        
|           |                                                          |        
|           | ${zControlUserid}                                                 |        
|           | ${zServantUserid}                                                 |
|           |                                                          |        
|           | See the z/OS eNetwork Communication Server IP            |        
|           | Configuration manual for the resolver search order.      |        
|           |                                                          |        
|           | Ensure the following user ID has read access to the data |        
|           | sets in your system parmlib concatenation:               |        
|           |                                                          |        
|           | ${zControlUserid}                                                |        
|           |                                                          |        
|           | ATTENTION:                                               |        
|           |                                                          |        
|           |  If operator commands are protected by the z/OS security |        
|           |  server at your installation, you must ensure that       |        
|           |  sufficient authority is given to WebSphere tasks to     |        
|           |  control operations.                                     |        
|           |                                                          |        
|           |  The Deployment Manager and Application Server           |
|           |  controller user ID (${zControlUserid}) needs the ability          |        
|           |  to perform operations on started tasks belonging        |        
|           |  to WebSphere Application Server for z/OS                |               
|           |                                                          |
|           |  The asynchronous administrator user ID, and any user    |        
|           |  ID used to run the federation job when the node agent   |        
|           |  is started automatically, need the authority to issue   |        
|           |  the MVS START command.                                  |        
|           |                                                          |        
|           |  If you are currently controlling MVS console command    |        
|           |  authority with SAF OPERCMDS profiles, grant the         |        
|           |  following authorities as indicated, substituting your   |        
|           |  own profile names:                                      |        
|           |                                                          |        
|           |  PERMIT  START_profile_name  CLASS(OPERCMDS)             |        
|           |          ID (${zControlUserid} ${zAdminAsynchTaskUserid})  ACCESS(UPDATE)           |        
|           |                                                          |        
|           |  PERMIT  STOP_profile_name  CLASS(OPERCMDS)              |        
|           |          ID (${zControlUserid})  ACCESS(UPDATE)                    |        
|           |                                                          |        
|           |  PERMIT  MODIFY_profile_name  CLASS(OPERCMDS)            |        
|           |          ID (${zControlUserid})  ACCESS(UPDATE)                    |        
|           |                                                          |        
|           |  PERMIT  CANCEL_profile_name  CLASS(OPERCMDS)            |        
|           |          ID (${zControlUserid})  ACCESS(UPDATE)                    |        
|           |                                                          |        
|           |  PERMIT  FORCE_profile_name  CLASS(OPERCMDS)             |        
|           |          ID (${zControlUserid})  ACCESS(UPDATE)                    |        
|           |                                                          |        
|           |  You must also grant the appropriate console command     |        
|           |  authority to any user ID that executes the              |        
|           |  startServer.sh or stopServer.sh script.                 |        
|           |                                                          |        
+-----------+----------------------------------------------------------+   
| BBOCCPY1  | User ID requirement:                                     |        
+-----------+     Authority to update the cataloged procedure library  |        
| Done:     |     ${zProclibName}                                      |
|           |                                                          |        
| By:       |                                                          |       
|           | This job copies the tailored cataloged procedures to     |        
|           | your procedure library.                                  |        
|           |                                                          |        
|           | ATTENTION: Be aware that you may overlay existing        |        
|           | members in the above data set.                           |        
|           |                                                          |        
+-----------+----------------------------------------------------------+
| BBOCCFS   | User ID requirement:                                     |
+-----------+     File system update authority (see above), and the    |
|           |     authority to allocate                                |
| Done:     |   ${zConfigHfsName}                                              |
|           |   ${zAppServerConfigHfsName}                                              |        
|           |                                                          |        
|           | ATTENTION: Skip this step if the mount points are        |
|           | already created.                                         |
|           |                                                          | 
|           | Before running this job:                                 |        
|           |                                                          |        
|           | Verify that the DD statements which define the data sets |        
|           | are valid for the storage rules defined on the target    |        
|           | system.                                                  |        
|           |                                                          |       
| By:       | This job:                                                |        
|           |                                                          |        
|           | o   Creates the following mount point directories        |        
|           |                                                          |        
|           |     ${zConfigMountPoint}                                           |
|           |     ${zAppServerConfigMountPoint}                                           |        
|           |                                                          |
<!-- if (${zFilesystemType} == HFS) -->
|           | o   Allocates the following configuration file system(s) |        
|           |     using the Hierarchical File System (HFS)             |        
|           |                                                          |        
|           |     ${zConfigHfsName}                                            |
<!-- if (${zAppServerFilesystemType} == HFS) -->                                
|           |     ${zAppServerConfigHfsName}                                            |
<!-- endif -->
<!-- endif -->
<!-- if (${zFilesystemType} == ZFS) -->
|           |                                                          |
|           | o   Allocates the following configuration file system(s) |        
|           |     using the z/OS Distributed File Service zSeries File |        
|           |     System (zFS)                                         |        
|           |                                                          |        
|           |     ${zConfigHfsName}                                            |
<!-- if (${zAppServerFilesystemType} == ZFS) -->
|           |     ${zAppServerConfigHfsName}                                            |
<!-- endif -->
<!-- if (${zAppServerFilesystemType} == HFS) -->
|           |                                                          |
|           | o   Allocates the following configuration file system    |        
|           |     using the Hierarchical File System (HFS)             |        
|           |                                                          |        
|           |     ${zAppServerConfigHfsName}                                           |
<!-- endif -->
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
<!-- if (${zAppServerFilesystemType} == ZFS) -->
|           |                                                          |
|           | o   Allocates the following configuration file system    |        
|           |     using the z/OS Distributed File Service zSeries File |        
|           |     System (zFS)                                         |        
|           |                                                          |        
|           |     ${zAppServerConfigHfsName}                                            |
<!-- endif -->
<!-- endif -->
|           |                                                          |        
|           |     and mounts them at the above mount points.           |        
|           |                                                          |
|           | DO NOT RUN THIS JOB IF:                                  |        
|           |   1. The configuration file systems already exist and    |        
|           |      are mounted at the desired mountpoints, or if       |        
|           |                                                          |        
|           |   2. The mount point directories are controlled by       |        
|           |      automount.  Either disable the automount rule for   |        
|           |      the configuration mount points while running this   |        
|           |      job, or perform the following steps manually:       |        
|           |                                                          |        
|           |      a. Allocate the configuration file system data sets.|        
|           |      b. Issue the following shell commands, which will   |        
|           |         also cause automount to mount the file systems   |        
|           |                                                          |        
|           |      chmod 775 ${zConfigMountPoint}                                |
|           |      chmod 775 ${zAppServerConfigMountPoint}                                | 
|           |                                                          |               
|           |      chown ${zAdminUserid}:${zConfigurationGroup}                             |
|           |         ${zConfigMountPoint}                                       |        
|           |                                                          |
|           |      chown ${zAdminUserid}:${zConfigurationGroup}                             |
|           |         ${zAppServerConfigMountPoint}                                       |        
|           |                                                          |
|           |                                                          |                
|           | BEFORE YOU BEGIN: The BBOCCFS job assumes your root      |        
|           | file system is mounted in read/write mode.  If the       |        
|           | root file system is not mounted in read/write mode,      | 
|           | manually create the directories                          |        
|           |                                                          |        
|           | ${zConfigMountPoint}                                              |
|           | ${zAppServerConfigMountPoint}                                               |        
|           |                                                          |        
|           | and any needed higher directories. Set file permissions  |        
|           | to 775 and set the owning user ID and group to ${zAdminUserid}  |        
|           | and ${zConfigurationGroup} before running BBOCCFS                      |        
|           |                                                          |        
|           | EXAMPLE: If you plan to use /wasv7config as your         |        
|           | directory, issue the following commands from within the  |        
|           | OMVS shell:                                              |        
|           |                                                          |        
|           |   mkdir -p -m 775 /wasv7config                           |        
|           |   chown -R ${zAdminUserid}:${zConfigurationGroup} /wasv7config|        
|           |                                                          |                                                                                                                                    
+-----------+----------------------------------------------------------+
| BBOCHFSA  | User ID requirement:                                     |
+-----------+     File system update authority (see above).            |
|           |                                                          |       
| Done:     | This job populates the previously-created configuration  |
|           | file systems and prepares them for profile creation.     |        
|           |                                                          |
|           | Note: If the SCEERUN data set is not in the system link  |        
|           | list, add that data set to STEPLIB for the CHECKV step   |        
|           | in BBOCHFSA.                                             | 
|           |                                                          |        
|           | Upon completion, examine the job output. Success is      |        
| By:       | indicated with a RC=0 in the job output.                 |        
|           |                                                          |        
+-----------+----------------------------------------------------------+
| BBOWWPFC  | User ID requirement:                                     |
+-----------+     File system update authority (see above).            |
|           |                                                          |
| Done:     | This job creates a profile (set of configuration files   |
|           | for a node) in the configuration file system.            |        
|           |                                                          |        
|           | Note: If the SCEERUN2 data set is not in the system link |        
|           | list, add that data set to STEPLIB for the LIBVSCRP,     |   
|           | CELPROFD and CELPROFN steps in BBOWWPFC                  |
|           |                                                          |       
|           |                                                          |        
| By:       | Upon completion, examine the job output. Success is      |        
|           | indicated by rc=0.                                       |        
|           |                                                          |        
|           | Note: If the BBOWWPFC (profile creation job) fails, you  |        
|           | must perform the following steps to remove the partially |        
|           | built profile:                                           |        
|           |                                                          |        
|           |   cd ${zConfigMountPoint}/                                         |        
|           |    ${zWasServerDir}                                              |        
|           |                                                          |        
|           |   ./bin/manageprofiles.sh -deleteAll                     |        
|           |                                                          |        
|           |   rm -R profiles                                         |        
|           |                                                          | 
|           |   cd ${zAppServerConfigMountPoint}/                                         |        
|           |    ${zAppServerWasServerDir}                                             |        
|           |                                                          |        
|           |   ./bin/manageprofiles.sh -deleteAll                     |        
|           |                                                          |        
|           |   rm -R profiles                                         |
|           |                                                          |       
|           | Then, correct the problem that caused BBOWWPFC to fail   |        
|           | and re-run the job                                       |       
|           |                                                          |
+-----------+----------------------------------------------------------+        
| --------  | All WebSphere Application Server processes require       |        
+-----------+ access to the Language Environment and System SSL load   |        
| Done:     | modules.                                                 |        
|           |                                                          |        
|           | If the SCEERUN, SCEERUN2 and System SSL load module      |        
|           | libraries are not in the system link list, add them to   |        
|           | the STEPLIB DD concatenation in each of the following    |        
|           | cataloged procedures in                                  |    
|           | ${zProclibName}:                                               |      
|           |                                                          |        
|           |     ${zControlProcName}                                             |        
|           |     ${zServantProcName}                                             |        
|           |     ${zAppServerControlProcName}                                             |        
|           |     ${zAppServerServantProcName}                                             |
|           |     ${zAppServerAdjunctProcName}                                             |        
|           |     ${zDaemonProcName}                                           |        
|           |                                                          |        
|           | and also add the full data set names, separated by       |        
|           | colons (:), to the STEPLIB variable in the shell scripts |        
|           |                                                          |        
|           |     ${zConfigMountPoint}/                                          |        
|           |      ${zWasServerDir}/                                           |        
|           |       profiles/default/bin/setupCmdLine.sh               |        
|           |                                                          |        
|           |     ${zAppServerConfigMountPoint}/                                          |        
|           |      ${zAppServerWasServerDir}/                                           |        
|           |       profiles/default/bin/setupCmdLine.sh               |        
| By:       |                                                          |        
|           | When modifying the setupCmdLine.sh script, do not        |        
|           | remove lines or comment them out, as this may cause      |        
|           | problems with automated updates to the script.           |        
|           |                                                          |        
|           | Add only those data sets which are NOT in the link list. |        
|           |                                                          |               
+-----------+----------------------------------------------------------+        
| --------  | Make sure Resource Recovery Services (RRS) is active.    |        
+-----------+ (See the online information center for setup             |        
| Done:     | instructions if necessary.) Look for the following       |        
|           | console message to verify that RRS was successfully      |
|           | started:                                                 |        
|           |                                                          |        
| By:       |                                                          |        
|           |   ASA2011I RRS INITIALIZATION COMPLETE. COMPONENT        |        
|           |     ID=SCRRS                                             |        
|           |                                                          |        
+-----------+----------------------------------------------------------+
| --------  | Start the Deployment Manager.                            |        
+-----------+                                                          |        
| Done:     | Issue the MVS command                                    |        
|           |                                                          |        
|           |   START ${zControlProcName},JOBNAME=${zServerShortName},                       |        
|           |      ENV=${zCellShortName}.${zNodeShortName}.${zServerShortName}             |        
|           |                                                          |
|           |                                                          |
| By:       | This command starts the Deployment Manager and also      |        
|           | starts the location service daemon. Wait until the       |        
|           | server is finished initializing before proceeding.       |        
|           |                                                          |        
|           | RESULT: The following message appears on the console and |        
|           | in the job log of ${zServerShortName}                               |        
|           |                                                          |        
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |        
|           |     z/OS CONTROL PROCESS ${zServerShortName}                        |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | Start the Node agent server.                             |        
+-----------+                                                          |        
| Done:     | Issue the MVS command                                    |        
|           |                                                          |        
|           |   START ${zAppServerControlProcName},JOBNAME=${zNodeAgentServerShortName},                       |        
|           |      ENV=${zCellShortName}.${zAppServerNodeShortName}.${zNodeAgentServerShortName}             | 
|           |                                                          |
| By:       | This command starts the node agent server.               |        
|           |                                                          |        
|           | RESULT: The following message appears on the console and |        
|           | in the job log of ${zNodeAgentServerShortName}.                              |        
|           |                                                          |        
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |        
|           |   z/OS CONTROL PROCESS ${zNodeAgentServerShortName}.                         |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | Start the Application Server                             |                            
+-----------+                                                          |        
| Done:     | Note: You must start the node agent before you start the |        
|           | Application Server, if the node agent has not already    |        
|           | been started.                                            |        
|           |                                                          |        
| By:       | Issue the MVS command                                    |
|           |                                                          |
|           |   START ${zAppServerControlProcName},JOBNAME=${zAppServerServerShortName},                       |        
|           |      ENV=${zCellShortName}.${zAppServerNodeShortName}.${zAppServerServerShortName}             |
|           |                                                          |
|           | This command starts the Application Server.              |        
|           |                                                          |        
|           | RESULT: The following message appears on the console and |        
|           | in the job log of ${zAppServerServerShortName}                              |        
|           |                                                          |        
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |        
|           |   z/OS CONTROL PROCESS ${zAppServerServerShortName}                           |        
|           |                                                          |        
+-----------+----------------------------------------------------------+
| To run these servers in reusable address spaces, add ",REUSASID=YES" |
| to the end of the START commands. See the article "Reusable address  |
| space" in the WebSphere Application Server for z/OS Information      |
| Center for more information, and important restrictions.             |
+----------------------------------------------------------------------+
                                                                                                                                                         
Note: Once your deployment manager is up and running, you can expand            
the WebSphere Application Server cell by federating existing stand-             
alone servers, or by creating and federating new managed nodes.  Use            
the customization tools to perform these operations.                                                           
                                                                                                                                                        
