<!-- ================================================================ -->         
<!-- PROPRIETARY-STATEMENT:                                           -->         
<!-- Licensed Material - Property of IBM                              -->         
<!--                                                                  -->         
<!-- 5724-I63, 5724-H88, 5655-N01, 5733-W61                           -->         
<!-- (C) Copyright IBM Corp. 1999, 2008                               -->         
<!-- All Rights Reserved                                              -->         
<!-- US Government Users Restricted Rights - Use, duplication or      -->         
<!-- disclosure restricted by GSA ADP Schedule Contract with IBM Corp.-->         
<!-- ================================================================ -->         
<!--                                                                  -->         
<!-- Change Activity:                                                 -->         
<!--                                                                  -->         
<!--   WS14568 H28W500 021118  PDML: Initial release.                 -->         
<!--   MD15332 H28W500 030108  PDML: Moved "Run install scripts"      -->         
<!--                                 section to before BBOWIAPP       -->         
<!--   MD15360 H28W500 030108  PDML: Add Step to create JCLLIB        -->         
<!--   MD15361 H28W500 030108  PDML: Updated cluster start section    -->         
<!--   MD15362 H28W500 030108  PDML: Updated BBOWCPY1                 -->         
<!--   MD15395 H28W500 030110  PDML: add BBOWCPY2                     -->         
<!--   MD15430 H28W500 030117  PDML: add SBBOLPA note                 -->         
<!--   WS14568.02 H28W500 030205 PDML: add a step to start the daemon -->         
<!--                                 remove the BBOWJCLL step         -->         
<!--                                 change WLM setup.                -->         
<!--                                 add BBOMCFG2 step.               -->         
<!--   MD15432 H28W500 030210  PDML: remove JCLLIBDS                  -->         
<!--   MD15808 H28W500 030212  PDML: change &WSNODE to &SYSNAME       -->         
<!--   MD15326 H28W500 030214  PDML: add warning to BBOWCPY1.         -->         
<!--   MD15863 H28W500 030215  PDG1: WLM ... &&SYSNAME and warning.   -->         
<!--   MD15867 H28W500 030215  PDML: change daemon start parameter.   -->         
<!--   MD16255 H28W500 030313  PDG1: update instructions.             -->         
<!--   MD16284 H28W500 030319  PDML: update ENV=.... for WLM.         -->         
<!--   MD16282 H28W500 030321  PDML: need read access to SYS1.TCPPARMS-->         
<!--                                 and SYS1.PARMLIB.                -->         
<!--   MD16289 H28W500 030325  PDML: updated some job names.          -->         
<!--   MD16389 H28W500 030402  PDML: add addNode step: BBOWADDN       -->         
<!--   MD16690 H28W500 030409  PDML: updated user requirement for jobs-->         
<!--   MD16742 H28W500 030416  PDML: updated start.                   -->         
<!--   MD17209 H28W500 030527  PDML: Correct RACF job names           -->         
<!--   MD17229 H28W500 030602  PDGK: Add BBOCR2FD.                    -->         
<!--   MD17286 H28W500 030620  PDG1: Adjust ownership                 -->         
<!--   MD17356 H28W500 030617  PDML: remove addNode step:  BBOWADDN   -->         
<!--   PQ75181 H28W500 030709  PDML: correct TCP/IP port infomation.  -->         
<!--   PQ74952 H28W500 030618  PDSS: Updates for ID defects MD16833,  -->         
<!--                                 MD17105,MD17106,MD17107,PQ74952  -->         
<!-- MD15508.2 H28W500 030721  PDML: Move BBODCFG2 after BBOCR2FD.    -->         
<!--   MD17621 H28W500 030725  PDG1: Additional changes for addNode   -->         
<!--   PQ75949 H28W500 030806  PDGK: Change BBOCR2FD instructions.    -->         
<!--   WS15621 H28W502 030826  PDRZ: Change oper command instructions -->         
<!--   PQ77867 H28W500 030909  PDML: change CBCONFIG to DMCONFIG.     -->         
<!--                                 change CNFGHFS  to DMFGHFS.      -->         
<!--   WS17709 H28W502 030930  PDGK: RACF Keyring changes.            -->         
<!--   MD18214 H28W502 031013  PDSS: Updated BBODIAPP instructions    -->         
<!--   PQ78664 H28W502 031024  PDSS: Added new prelim PARMLIB step    -->         
<!--   MD18797 H28W502 031204  PDSS: Fixed &PARMLIB. overflow problem -->         
<!--   PQ83464 H28W510 041102  PDSS: Updated userid for BBOMCFGU      -->         
<!--   MD19809 H28W510 040904  PDML: remove BBOMCFGU.                 -->         
<!--   238129  H28W600 100804  PDML: update instructions for V6.      -->         
<!--   244703  H28W600 111904  PDML: update instructions for V6.      -->         
<!--   244860  H28W600 120204    DB: Add TCPIP instructions for SI    -->         
<!--                                 ports                            -->         
<!--   246983  H28W600 121604    DB: Revise instructions based on     -->         
<!--                                 new dataset panels               -->         
<!--   249091  H28W601 011005    DB: Updates based on review comments -->         
<!--   247922  H28W601 011905    DB: BBODBRAC instruction update      -->         
<!--   251673  H28W601 012605    DB: More review updates              -->         
<!--   253951  H28W601 021505    DB: Add BBODCFGW to instructions     -->         
<!--   257024  H28W601 022205    DB: BBOCBRAK is mentioned where      -->         
<!--                                 BBODBRAK should                  -->         
<!--   241041  H28W601 032205  PDSS: Added instructions for when      -->         
<!--                                 BBOWWPFD fails on second try     -->         
<!-- LIDB3534-14 H28W602 041205  DB: Add BBODPROX job to instructions -->         
<!--   259928  H28W602 041405    DB: Only  generate BBORTSS5 section  -->         
<!--                                 if answer for in STEPLIB is Y    -->         
<!--   253275  H28W602 041505    DB: remove reference to BBOWTR       -->         
<!--   270793  H28W602 042505    DB: remove BBODPROX job              -->         
<!--   269195  H28W602 042705    DB: remove references to RRS         -->         
<!--   271696  H28W602 042805    DB: add text for BBODCFGW            -->         
<!--   262089  H28W602 042805    DB: remove WLM static instructions   -->         
<!--   271956  H28W602 042805    DB: add BBODPROX                     -->         
<!--   274807  H28W602 051105    DB: BBODCFGW should be run as admin  -->         
<!--   279689  H28Wxxx 053105    DB: remove BBODPROX                  -->         
<!--   279429  H28W602 052705  PDML: add directory verifications step.-->         
<!--   281074  H28W602 060305  PDML: display the dir verfication step -->         
<!--                                 only if USERHOME is not tmp.     -->         
<!--   283304  H28W602 061305  PDML: remove dir verfication step      -->         
<!--  PK07374  H28W602 062105  PDML: add directory verifications step.-->         
<!--  PK06797  H28W602 062205    DB: add BBOERRLG                     -->         
<!--  PK07293  H28W602 062205    DB: add BBOSCHED and BBOIPCSP        -->         
<!--   290470  H28W602 071805  PDML: remove BBOSGSK.                  -->         
<!-- LIDB3561-19 H28W610 071805  PDML: IHS update.                    -->         
<!-- LIDB2634  H28W610 083005  PDML: security out of the box update.  -->         
<!--   302474  H28W610 090105  PDML: update instruction for security. -->         
<!--   306104  H28W610 091805    DB: add admin console ports to       -->         
<!--                                 TCPIP section                    -->         
<!--   306432  H28W610 091905    DB: reword admin console port desc   -->         
<!--   311865  H28W610 100805    DB: remove SCEERUN items             -->         
<!--   313366  H28W610 101405  PDML: move text around ERRLOG.         -->         
<!--   317828  H28W610 111205  PDML: add OMVS WLM setup instructions. -->         
<!--   319766  H28W610 110705    DB: remove HTTP transport ports      -->         
<!--   324253  H28W610 111605    DB: change CB* variables to DM       -->         
<!--   324527  H28W610 111605    DB: fix references to AppServer      -->         
<!--   322399  H28W610 111605    DB: remove webserver jobs            -->         
<!--   325782  H28W610 112105    DB: change BBORTSS5 to BBORTS61      -->         
<!--   330776  H28W610 121405    DB: update instructions based on     -->         
<!--                                 change to SBBOLPA/SBBOLOAD       -->         
<!--   337853  H28W610 011206    DB: fix some typos                   -->         
<!--   333384  H28W610 011306    DB: add zfs support                  -->         
<!--   336558  H28W610 011606    DB: reword text after dmgr config    -->         
<!--  333384.1 H28W610 011906    DB: filesystem should be two words   -->         
<!--  337515   H28W610 012306    DB: updates for STEPLIB changes      -->         
<!--  330804   H28W610 012406    DB: add automount warning            -->         
<!--  342400   H28W610 013006    DB: change FILEZFS to FSTYPE         -->         
<!--  342461   H28W610 013106    DB: update OPERCMDs instructions     -->         
<!--  338132   H28W610 020606  PDML: add SBBGLOAD.                    -->         
<!--  341403   H28W610 020906  PDML: add a note for BBOSBRAM          -->         
<!--  354688   H28W610 031406    DB: LE/SSL datasets don't go in LPA  -->         
<!--  356728   H28W610 032406    DB: use DMFSTYPE                     -->         
<!-- PK20049   H28W610 042206    DB: instructions for LE in STEPLIB   -->         
<!--  364931   H28W610 042406    DB: updates for non root install     -->         
<!--  373993   H28W610 082206    DB: SAF profile update for zFS       -->         
<!--  370154   H28W610 083106    DB: Add verify stmt for HFS jobs     -->         
<!--  390937   H28W610 100106    DB: 64-bit bit instruction changes   -->         
<!--  348320   H28W610 102506    DB: updates for asterisk id          -->         
<!--  400982   H28W610 102606    DB: Add text for AUTOMOVE            -->         
<!--  402402   H28W610 110106    DB: Reword text for automove         -->         
<!--  411108   H28W610 121206    DB: Fix possible length error        -->         
<!--  412596   H28W610 010307    DB: Add SBBGLOAD references          -->         
<!--  412597   H28W610 010807    DB: fix minor text issues            -->
<!-- LIDB4489-16 H28W700 040107  DB: 64-bit updates                   -->
<!--  425357   H28W610 040907    DB: use aggrgrow option for ZFS      -->         
<!--  447303   V7.0    070614  PDOP: Userid simplification            -->
<!--  447528   V7.0   20070629 PXTN: Convert zmpt variables           --> 
<!-- LIDB4194-52 V7.0  040107  PDOP: Flexible management              -->
<!--LIDB4302-11.10 V7.0 070824    DB: Rename file system job          -->
<!--  465452   V7.0    101907  PDOP: Updated profile cleanup info     -->
<!--  LIDB4689  V7.0    20071024 DMB: Move load modules to hfs        -->
<!--  466649   V7.0    102507  PDOP: Remove refs to config dialog     -->
<!--  484621   V7.0    112807  PDOP: Updated "Z" proclib references   -->
<!--   488222  V7.0    121207  PDOP: Added admin agent and jmgr refs  -->
<!--   489808  V7.0    122007   PXT: Change order of BBODCPY1 to run  -->
<!--  492063   V7.0    011507   DMB: Use one step RACF jobs           -->
<!--  502633   V7.0    030308  PDOP: Removed use of "InfoCenter"      -->
<!--  504724   V7.0    032008  PDOP: Added prod file system directions-->
<!--  500745  V7.0    20080407 PXT: Rename from BBOxBRAJ to BBOxBRAK  -->
<!--511429.1 V7.0   20080519   DMB: Create SR id in bbosbrac          -->
<!--  538461   V7.0   20080723 PDOP: Add SCLBDLL2 to system link list -->
<!--  546577   V7.0   20080829 PDOP: Add daemon id                    -->
<!--  567032   V7.0   20081203 PDOP: Clean up                         -->
<!--  PK70886  V7.0   20081216  DMB: Add region size warning info     -->
<!--  567032.1 V7.0   20090116 PDOP: Additional clean up              -->
<!-- PK83899   V7.0   20090413 DMB: Update section on SCHEDxx member  -->
<!-- PM12309  V7.0    20100721 DMB: Updates for REUSASID              -->
<!--  715560   V8.0   20110908 PDOP: Show WAS version                 -->
<!--  745081   V7.0   20130306 PDOP: Update SAF profile privileges    -->         
<!-- ================================================================ -->         
                                                                                                                                                                
-----------------------------------------------                                 
WebSphere Application Server for z/OS V7.0 customization instructions:

<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
Deployment manager ${zServerShortName}  (cell ${zCellShortName}, node ${zNodeShortName})  
<!-- endif -->
<!-- if (${serverType}==JOB_MANAGER) --> 
Job manager ${zServerShortName}  (cell ${zCellShortName}, node ${zNodeShortName})  
<!-- endif -->
<!-- if (${serverType}==ADMIN_AGENT) --> 
Administrative agent ${zServerShortName}  (cell ${zCellShortName}, node ${zNodeShortName})  
<!-- endif -->
Tailored on ${ZDATE} at ${ZTIMEL} by ${ZUSER}                                 
WCT version ${wctVersion} build ${wctBuild} 
                                                                                                                                                               
The customization tools have created jobs based on the information you          
provided. These instructions tell you how to modify the operating               
system and run the jobs to customize WebSphere for z/OS.                        
                                                                                                                                                                
RULES:                                                                          
                                                                                                                                                               
1.  If you created the target data sets (*.CNTL and *.DATA) on another          
    (driving) system, you must copy them to the target system and give          
    them the same data set names.                                               
                                                                                                                                                               
2.  You must perform these instructions on your target system.                  
                                                                                                                                                               
Doing manual configuration updates                                              
                                                                                
----------------------------------                                              
                                                                                                                                                               
You must perform the following manual steps on the target z/OS system 
before running the WebSphere for z/OS configuration jobs.  
                                                                         
1.  Update BLSCUSER. Refer to member BBOIPCSP in                                
                                                                         
    ${zTargetHLQ}.CNTL                                                                   
                                                                        
    In order to use the IPCS support provided by the product, append            
    the contents of this member to the BLSCUSER member in your IPCSPARM         
    or system PARMLIB datasets.                                                 
                                                                                                                                                              
    -------------------------------------------------------------------         
                                                                        
2.  Update SCHEDxx. Refer to member BBOSCHED in                                 
                                                                        
    ${zTargetHLQ}.CNTL                                                                  
                                                                       
    In order to set the correct program properties for the WebSphere            
    for z/OS run-time executables, append the contents of this member           
    to the SCHEDxx member in your system PARMLIB concatenation.                 
                                                                     
    Note: When you are finished, issue the command SET SCH=xx to
	activate SCHEDxx and load a new program properties table.  This
	action does not need to be performed if the target z/OS system is
	at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED
	member contains already exists in the IBM-supplied PPT table at
	those z/OS levels.                
                                                                              
    -------------------------------------------------------------------         
                                                                          
3.  Update your active BPXPRMxx member to have the following WebSphere          
    for z/OS configuration file system:                                         
                                                                       
    ${zConfigHfsName}                                                                   
                                                                         
    mounted at:                                                                 
                                                                        
    ${zConfigMountPoint}                                                                  
                                                                        
    in read/write mode.                                                         
                                                                                                                                                             
    EXAMPLE:                                                                    
                                                                                                                                                         
<!-- if (${zFilesystemType} == ZFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                
          TYPE(${zFilesystemType})                                                      
          MODE(RDWR) PARM('AGGRGROW')
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
       MOUNT FILESYSTEM('${zConfigHfsName}')                                            
         MOUNTPOINT('${zConfigMountPoint}')                                                
          TYPE(${zFilesystemType})                                                      
          MODE(RDWR)
<!-- endif -->
                                                                         
    If you are configuring in a sysplex environment, you may wish to            
    add the NOAUTOMOVE parameter as follows:                                    

<!-- if (${zFilesystemType} == ZFS) -->
        MOUNT FILESYSTEM('${zConfigHfsName}')                                           
         MOUNTPOINT('${zConfigMountPoint}')                                                
          TYPE(${zFilesystemType})                                                      
          MODE(RDWR) PARM('AGGRGROW') SYSNAME(${zSystemName}) NOAUTOMOVE
<!-- endif -->
<!-- if (${zFilesystemType} == HFS) -->
        MOUNT FILESYSTEM('${zConfigHfsName}')                                           
         MOUNTPOINT('${zConfigMountPoint}')                                                
          TYPE(${zFilesystemType})                                                      
          MODE(RDWR) SYSNAME(${zSystemName}) NOAUTOMOVE
<!-- endif -->
                                                                      
    The NOAUTOMOVE parameter in the example above prevents the                  
    configuration file system from being mounted on a different z/OS            
    system in a shared file system configuration, which could cause             
    performance problems.

<!-- if (${zFilesystemType} == ZFS) -->
    If you have specified "aggrgrow=on" in your IOEFSPRM parmlib member,
    you can omit the AGGRGROW parm shown in the above examples
<!-- endif -->  
                                                                                                                                                    
    -------------------------------------------------------------------         
                                                                                                                                                          
<!-- import documents/cntl/productFileSystem.txt -->
                                                                                
    -------------------------------------------------------------------         
                                                                                                                                                         
5.  Update TCP/IP by reserving the following ports for WebSphere for            
    z/OS:                                                                       
                                                                                                                                                              
       SOAP JMX Connector port                       - ${zSoapPort}                
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
       CELL DISCOVERY ADDRESS port                   - ${zCellDiscoveryPort}               
<!-- endif -->
       ORB port                                      - ${zOrbListenerPort}               
<!-- if (${zOrbListenerSslPort} != 0) -->
       ORB SSL port                                  - ${zOrbListenerSslPort}               
<!-- endif -->
       Administrative console port                   - ${zAdminConsolePort}                
       Administrative console secure port            - ${zAdminConsoleSecurePort}               
                                                                        
       Administrative local port                     - ${zAdminLocalPort}                                                                   
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
       High Availability Manager Communications port - ${zHighAvailManagerPort}               
<!-- endif -->
                                                                      
       Daemon IP port                                - ${zDaemonPort}               
       Daemon SSL port                               - ${zDaemonSslPort}               
                                                                                                                                                           
    View member BBOTCPID in                                                     
                                                                              
    ${zTargetHLQ}.CNTL                                                                   
                                                                        
<!-- start of changed text for TCPDD                                               -->
                                                                                
    Add the contents of this member to the PORT section of the file             
    referenced by the DD statement for the TCP/IP profile in the                
    TCP/IP start procedure. Cut and paste from this member into the             
    data set used by your installation.                                         
                                                                                
<!-- end of changed text for TCPDD                                                 -->
                                                                         
    ATTENTION: If another application has already reserved any of these         
    ports for its own use, you must resolve the resulting conflict              
    before you continue. Do not manually update the customization jobs
    and data files; instead, use the customization tools to regenerate      
    the customization jobs, data, and instructions.                    
                                                                        
    Note:  It is recommended that the IPCONFIG, UDPCONFIG, and                  
    TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to             
    only allow super users or APF-authorized user applications to bind          
    to privileged ports (1-1024), unless the SAF keyword is specified           
    and the user ID binding to the port is permitted to the SAF                 
    resource.  It is left up to the users' discretion to determine              
    whether this is a viable course of action given the users' specific         
    application/port requirements.                                             
                                                                        
    For more information please consult:                                        
                                                                        
    z/OS Communication Server IP Configuration Guide            
                                                                                                                                                                                                                          
    -------------------------------------------------------------------         
                                                                      
6.  WebSphere for z/OS customization assumes that the following system          
    data sets are in the system link list:                                      
                                                                       
    Language Environment     SCEERUN                                            
                             SCEERUN2                                           
                                                                         
    System SSL               SIEALNKE
    
    Support for 64-bit       SCLBDLL2
                                                                      
    See the Language Environment Customization manual and the System            
    SSL Programming manual for your z/OS release for advice on placing          
    members from the libraries into the system link pack area.                  
                                                                     
    Placing these data sets in the link list insulates your WebSphere           
    for z/OS configuration from changes in data set names (for example,         
    when migrating to newer releases of z/OS).                                                
                                                                      
    If the Language Environment or System SSL load module libraries are         
    not in your system link list, you must perform the following steps          
    before starting any WebSphere Application Server for z/OS servers:          
                                                                      
    - Make sure the data sets are APF-authorized                                
    - Complete the optional step below to add the data sets to STEPLIB          
      in the server JCL and setupCmdLine.sh script(s).                          
                                                                   
    If you regenerate server cataloged procedures at any point, make            
    sure the data sets are added to the new cataloged procedures.
                                                                       
    -------------------------------------------------------------------         
                                                                                                                                                            
Running the customized jobs                                                     
                                                                                
---------------------------                                                     
                                                                                                                                                              
The customization tools built a number of batch jobs with the                  
information you supplied. You must run the jobs in the order listed               
below using user IDs with the appropriate authority.                            
                                                                       
<!-- import documents/cntl/fileSysUpdateAuth.txt -->
                                                                                
                                                                        
BEFORE YOU BEGIN: Complete the section above entitled "Doing manual             
configuration updates".                                                         
                                                                                                                                                            
Follow the table below, which lists in order the jobs you must submit           
and the commands you must enter. Special handling notes are included            
in the table. All jobs are members of                                           
                                                                                                                                                             
${zTargetHLQ}.CNTL

By default, the customization jobs below are generated with REGION=0M.  
If this is not an allowable value on your target system, you may need to
modify this value for your environment.  Your system must allow a       
private region of sufficient size to allow the running of a Java Virtual
Machine Region with a maximum heap specification of 256 Megabytes       
(i.e., -Xmx256m).  Installation constraints that limit the region size  
or system exits that restrict the region a job is running in, may cause 
the customization jobs to fail due to a JVM error.  In the event of an  
Out of Memory (OOM) failure due to inadequate native storage, you must    
remove this constraint in order to successfully install WebSphere for   
z/OS.                                                                   
                                                                                                                                                               
Attention: After submitting each job, carefully check the output.               
Errors may exist even when all return codes are zero.                           
                                                                        
+-----------+----------------------------------------------------------+        
|           | The BBOSBRAK and BBOSBRAM jobs do not need to be run if  |
|           | the indicated groups, user IDs and directories already   |
|           | exist with the correct gid, uid and ownership permission |
|           | values, as given below.                                  |        
|           |                                                          |        
|           | In order for RACF to automatically select an unused UID  |        
|           | or GID value for WebSphere Application Server user IDs   |        
|           | and groups:                                              |        
|           |                                                          |        
|           | - The RACF profile SHARED.IDS must be defined.           |        
|           | - The RACF profile BPX.NEXT.USER must be define and used |        
|           |   to indicate the ranges from which UID and GID values   |        
|           |   are to be selected.                                    |        
|           |                                                          |        
|           | See the article "Preparing the Security Server (RACF)"   |        
|           | in the WebSphere Application Server for z/OS online      |        
|           | information center. For more information, consult        |        
|           | Chapter 20, "RACF and z/OS Unix", in the z/OS Security   |        
|           | Server RACF Security Administrator's Guide (SA22-7683).  |        
+-----------+----------------------------------------------------------+        
| BBOSBRAK  |  User ID requirement: RACF special authority.            |        
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create common     |
|           | WebSphere for z/OS groups and user IDs                   |
| By:       |                                                          |
|           | Note: A uid or gid value of * indicates that the OS      |        
|           | security system is to select an unused UID or GID value  |        
|           |                                                          |
|           |  Administrator user ID:     ${zAdminUserid} (uid ${zAdminUid})      |
|           |  Control user ID:           ${zControlUserid} (uid ${zControlUid})      |
|           |  Servant user ID:           ${zServantUserid} (uid ${zServantUid}) |        
|           |  Configuration group:       ${zConfigurationGroup} (gid ${zConfigurationGroupGID})      |        
|           |  Servant group:             ${zServantGroup} (gid ${zServantGroupGID})      |        
|           |  Local user group:          ${zLocalUserGroup} (gid ${zLocalUserGroupGID})      |        
|           |                                                          |        
|           | The commands are located in member BBOSBRAC of data set  |        
|           | ${zTargetHLQ}.DATA.                                      |        
|           |                                                          |        
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | This job creates the WebSphere administrator ID ${zAdminUserid}|        
|           | without a password (or password phrase).  You must       |
|           | assign this user ID a password (or password phrase) that |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           | complies with your institution standards. This is also   |
|           | the password (or password phrase) that will be used when |
|           | logging on to the WebSphere Application Server           |
|           | administrative console.                                  |        
<!-- endif -->
<!-- if (${zAdminSecurityType} != websphereForZos) -->
|           | complies with your institution standards.                |
<!-- endif -->
|           |                                                          |        
|           | Enter the following RACF command to assign a password:   |        
|           |                                                          |        
|           |   ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED   |
|           |                                                          |        
|           | Enter the following RACF command to assign a             |        
|           | password phrase:                                         |        
|           |                                                          |        
|           |   ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED    |
|           |                                                          |
|           | If you are using a different security system, make sure  |        
|           | that the ${zAdminUserid} user ID has a password or       |
|           | password phrase.                                         |
|           |                                                          |
|           | To use RACF password phrase support, your target system  |
|           | must be at z/OS Version 1.9 or above.                    |       
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBOSBRAK.                                                |        
|           |                                                          |        
|           | When this step is complete, all groups and user IDs      |        
|           | listed above for job BBOSBRAK should be defined in the   |        
|           | RACF database on each target system for the cell.        |        
|           | Note: the WAS administrator user ID ${zAdminUserid} MUST have |
|           | the WAS configuration group ${zConfigurationGroup} as its default |
|           | OMVS group.                                              |
+-----------+----------------------------------------------------------+        
| BBOSBRAM  | User ID requirement:                                     |        
+-----------+     File system update authority (see above).            |        
|           |                                                          |        
| Done:     | This job creates home directories for WebSphere for z/OS |        
|           | user IDS. These home directories will be subdirectories  |        
|           | of ${zUserIDHomeDirectory}                                            |        
| By:       |                                                          |        
|           | This job will:                                           |        
|           |                                                          |        
|           | Create the following directory with permission bits 755: |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}                                              |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zConfigurationGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zConfigurationGroup}                                     |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zServantGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zServantGroup}                                     |        
|           |                                                          |        
|           | Create the following directory with ownership            |        
|           | ${zControlUserid}:${zLocalUserGroup} and permission bits 770:               |        
|           |                                                          |        
|           |  ${zUserIDHomeDirectory}/${zLocalUserGroup}                                     |        
|           |                                                          |        
|           | This job should be run on each z/OS system that will     |        
|           | host WebSphere Application Server nodes using these      |        
|           | WebSphere for z/OS common groups and owner user ID.      |        
|           | After execution, verify that the directories have been   |        
|           | created with the correct permissions on each system.     |        
|           |                                                          |        
|           | If these directories already exist with the specified    |        
|           | ownership and permission on a target system, then this   |        
|           | job does not need to be run on that system.              |        
|           |                                                          |        
|           | ATTENTION: If the directory                              |        
|           |  ${zUserIDHomeDirectory}                                               |        
|           | is used by applications other than WebSphere Application |        
|           | Server, make sure that the permissions set by            |        
|           | BBOSBRAM (755) are appropriate, or change them manually. |        
|           | This directory must be world-readable for Websphere      |        
|           | Application Server to run correctly.                     |       
+-----------+----------------------------------------------------------+        
| BBODBRAK  | User ID requirement: RACF special authority.             |        
+-----------+                                                          |        
| Done:     | This job executes the RACF commands to create RACF users |
|           | and profiles required by this WebSphere for z/OS node.   |
| By:       |                                                          |
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
<!-- endif -->
<!-- if (${zAdminSecurityType} != websphereForZos) -->
<!-- if (${zDaemonUserid}token != token) -->
|           | Note: A uid value of * indicates that the OS security    |
|           | system is to select an unused UID value.                 |
|           |                                                          |
<!-- endif -->
<!-- endif -->
<!-- if (${zAdminSecurityType} == websphereForZos) -->
|           |  Unauthenticated user ID:   ${zAdminUnauthenticatedUserid} (uid ${zAdminUnauthenticatedUid}) |
<!-- endif -->
<!-- if (${zDaemonUserid}token != token) -->
|           |  Daemon user ID:            ${zDaemonUserid} (uid ${zDaemonUid}) |
<!-- endif -->
|           |                                                          |        
|           | The commands are located in member BBODBRAC of data set  |        
|           | ${zTargetHLQ}.DATA.                                      |        
|           |                                                          |
|           | Carefully review these definitions with your security    |        
|           | administrator.                                           |
|           |                                                          |
|           | RESULT: You may receive errors, such as INVALID USER     |        
|           | messages, from this job because a user ID, group  or     |        
|           | profile is already defined.  Make sure the existing      |        
|           | user ID, group or profile has the same characteristics   |        
|           | as the user ID, group or profile being created by        |        
|           | BBODBRAK.                                                |        
+-----------+----------------------------------------------------------+        
| --------  | Check user ID authorizations.                            |        
+-----------+                                                          |        
| Done:     | Make sure the ${zConfigurationGroup} group has read access to all     |        
|           | WebSphere product data sets, as well as to any other     |        
|           | data sets which will be placed in WebSphere for z/OS     |        
|           | cataloged procedure STEPLIB concatenations.              |        
|           |                                                          |        
|           | Make sure the following user IDs have read access to     |        
| By:       | the resolver configuration file in use on your system.   |        
|           | Depending on your IP setup, this file may be             |        
|           | /etc/resolv.conf, SYS1.TCPPARMS(TCPDATA), or another     |        
|           | data set.                                                |        
|           |                                                          |        
|           | ${zControlUserid}                                                 |        
|           | ${zServantUserid}                                                 |        
|           |                                                          |        
|           | See the z/OS eNetwork Communication Server IP            |        
|           | Configuration manual for the resolver search order.      |        
|           |                                                          |        
|           | Ensure the following user ID has read access to the data |        
|           | sets in your system parmlib concatenation:               |        
|           |                                                          |        
|           | ${zControlUserid}                                        |        
<!-- if (${zDaemonUserid}token != token) -->
<!-- if (${zDaemonUserid} != ${zControlUserid}) -->
|           | ${zDaemonUserid}                                         |        
<!-- endif -->
<!-- endif -->
|           |                                                          |        
|           | ATTENTION:                                               |        
|           |                                                          |        
|           |  If operator commands are protected by the z/OS security |        
|           |  server at your installation, you must ensure that       |        
|           |  sufficient authority is given to WebSphere tasks to     |        
|           |  control operations.                                     |        
|           |                                                          |        
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
|           |  The deployment manager controller user ID (${zControlUserid})     |        
<!-- endif -->
<!-- if (${serverType}==JOB_MANAGER) --> 
|           |  The job manager controller user ID (${zControlUserid})     |        
<!-- endif -->
<!-- if (${serverType}==ADMIN_AGENT) --> 
|           |  The administrative agent controller user ID (${zControlUserid})   |        
<!-- endif -->
|           |  needs the ability to perform operations on started      |        
|           |  tasks belonging to WebSphere Application Server for     |        
|           |  z/OS.                                                   |        
|           |                                                          |        
|           |  The asynchronous administrator user ID, and any user    |        
|           |  ID used to run the federation job when the node agent   |        
|           |  is started automatically, need the authority to issue   |        
|           |  the MVS START command.                                  |        
|           |                                                          |        
|           |  If you are currently controlling MVS console command    |        
|           |  authority with SAF OPERCMDS profiles, grant the         |        
|           |  following authorities as indicated, substituting your   |        
|           |  own profile names:                                      |        
|           |                                                          |        
|           |  PERMIT  START_profile_name  CLASS(OPERCMDS)             |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)                   |        
|           |                                                          |        
|           |  PERMIT  STOP_profile_name  CLASS(OPERCMDS)              |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)                   |        
|           |                                                          |        
|           |  PERMIT  MODIFY_profile_name  CLASS(OPERCMDS)            |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)                   |        
|           |                                                          |        
|           |  PERMIT  CANCEL_profile_name  CLASS(OPERCMDS)            |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)                   |        
|           |                                                          |        
|           |  PERMIT  FORCE_profile_name  CLASS(OPERCMDS)             |        
|           |          ID (${zControlUserid} )  ACCESS(UPDATE)                   |        
|           |                                                          |        
|           |  You must also grant the appropriate console command     |        
|           |  authority to any user ID that executes the              |        
|           |  startServer.sh or stopServer.sh script.                 |        
|           |                                                          |
+-----------+----------------------------------------------------------+
| BBODCPY1  | User ID requirement:                                     |        
+-----------+     Authority to update the cataloged procedure library  |        
| Done:     |     ${zProclibName}                                      |
|           |                                                          |        
| By:       |                                                          |        
|           |                                                          |        
|           | This job copies the tailored cataloged procedures to     |        
|           | your procedure library.                                  |        
|           |                                                          |        
|           | ATTENTION: Be aware that you may overlay existing        |        
|           | members in the above data set.                           |        
|           |                                                          |        
+-----------+----------------------------------------------------------+         
| BBODCFS   | User ID requirement:                                     |        
+-----------+     File system update authority (see above), and the    |        
|           |     authority to allocate                                |        
|           |        ${zConfigHfsName}                                 |        
| Done:     |                                                          |        
|           |                                                          |        
|           | ATTENTION: Skip this step if the mount point is already  |        
| By:       | created, such as for the stand-alone Application Server. |        
|           |                                                          |        
|           | Before running this job:                                 |        
|           |                                                          |        
|           | Verify that the DD statement which defines the data set  |        
|           | is valid for the storage rules defined on the target     |        
|           | system.                                                  |        
|           |                                                          |        
|           | This job:                                                |        
|           |                                                          |        
|           | o   Creates a mount point directory                      |        
|           |                                                          |        
|           |     ${zConfigMountPoint}                                 |        
|           |                                                          |        
|           | o   Allocates the configuration file system              |        
|           |                                                          |        
|           |     ${zConfigHfsName}                                    |        
|           |                                                          |        
|           |     and mounts it at the above mount point.              |        
|           |                                                          |        
|           | DO NOT RUN THIS JOB IF:                                  |        
|           |   1. The configuration file system already exists and is |        
|           |      mounted at the desired mountpoint, or if            |        
|           |                                                          |        
|           |   2. The mount point directory is controlled by          |        
|           |      automount.  Either disable the automount rule for   |        
|           |      the configuration mount point while running this    |        
|           |      job, or perform the following steps manually:       |        
|           |                                                          |        
|           |      a. Allocate the configuration file system data set. |        
|           |      b. Issue the following shell commands, which will   |        
|           |         also cause automount to mount the file system    |        
|           |                                                          |        
|           |      chmod 775 ${zConfigMountPoint}                      |        
|           |                                                          |        
|           |      chown ${zAdminUserid}:${zConfigurationGroup}        |        
|           |       ${zConfigMountPoint}                               |        
|           |                                                          |        
|           | BEFORE YOU BEGIN: The BBODCFS job assumes your root      |        
|           | file system is mounted in read/write mode.  If the root  |        
|           | file system is not mounted in read/write mode, manually  |        
|           | create the directory                                     |        
|           |                                                          |        
|           | ${zConfigMountPoint}                                     |        
|           |                                                          |        
|           | and any needed higher directories. Set file permissions  |        
|           | to 775 and set the owning user ID and group to ${zAdminUserid}|        
|           | and ${zConfigurationGroup} before running BBODCFS.       |        
|           |                                                          |        
|           | EXAMPLE: If you plan to use /wasv7config as your         |        
|           | directory, issue the following commands from within the  |        
|           | OMVS shell:                                              |        
|           |                                                          |        
|           |   mkdir -p -m 775 /wasv7config                           |        
|           |   chown -R ${zAdminUserid}:${zConfigurationGroup} /wasv7config|
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| BBODHFSA  | User ID requirement:                                     |        
+-----------+     File system update authority (see above).            |        
|           |                                                          |        
| Done:     | This job populates the previously-created configuration  |
|           | file system and prepares it for profile creation.        |        
|           |                                                          |        
|           | Note: If the SCEERUN data set is not in the system link  |        
|           | list, add that data set to STEPLIB for the CHECKV step   |        
|           | in BBODHFSA.                                             |        
|           |                                                          |        
|           | Upon completion, examine the job output. Success is      |        
| By:       | indicated with a RC=0 in the job output.                 |        
|           |                                                          |        
+-----------+----------------------------------------------------------+               
| BBOWWPFD  | User ID requirement:                                     |        
+-----------+     File system update authority (see above).            |        
|           |                                                          |        
| Done:     | This job creates a profile (set of configuration files   |
|           | for a node) in the configuration file system.            |        
|           |                                                          |        
|           | Note: If the SCEERUN2 data set is not in the system link |        
|           | list, add that data set to STEPLIB for the LIBVSCRP and  |        
|           | WPROFILE steps in BBOWWPFD.                              |        
|           |                                                          |        
| By:       | Upon completion, examine the job output. Success is      |        
|           | indicated by rc=0.                                       |        
|           |                                                          |        
|           | Note: If the BBOWWPFD (profile creation job) fails, you  |        
|           | must perform the following steps to remove the partially |        
|           | built profile:                                           |        
|           |                                                          |        
|           |   cd ${zConfigMountPoint}/                                         |        
|           |    ${zWasServerDir}                                              |        
|           |                                                          |        
|           |   ./bin/manageprofiles.sh -deleteAll                     |        
|           |                                                          |        
|           |   rm -R profiles                                         |        
|           |                                                          |        
|           | Then, correct the problem that caused BBOWWPFD to fail   |        
|           | and re-run the job                                       |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | All WebSphere Application Server processes require       |        
+-----------+ access to the Language Environment and System SSL load   |        
| Done:     | modules.                                                 |        
|           |                                                          |        
|           | If the SCEERUN, SCEERUN2 and System SSL load module      |        
|           | libraries are not in the system link list, add them to   |        
|           | the STEPLIB DD concatenation in each of the following    |        
|           | cataloged procedures in                                  |        
|           | ${zProclibName}:                                               |        
|           |                                                          |        
|           |     ${zControlProcName}                                             |        
|           |     ${zServantProcName}                                             |        
|           |     ${zDaemonProcName}                                           |        
|           |                                                          |        
|           | and also add the full data set names, separated by       |        
|           | colons (:), to the STEPLIB variable in the shell script  |        
|           |                                                          |        
|           |     ${zConfigMountPoint}/                                          |        
|           |      ${zWasServerDir}/                                           |        
|           |       profiles/default/bin/setupCmdLine.sh               |        
| By:       |                                                          |        
|           | When modifying the setupCmdLine.sh script, do not        |        
|           | remove lines or comment them out, as this may cause      |        
|           | problems with automated updates to the script.           |        
|           |                                                          |        
|           | Add only those data sets which are NOT in the link list. |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | Make sure Resource Recovery Services (RRS) is active.    |        
+-----------+ (See the online information center for setup             |        
| Done:     | instructions if necessary.) Look for the following       |        
|           | console message to verify that RRS was successfully      |
|           | started:                                                 |        
|           |                                                          |        
| By:       |                                                          |        
|           |   ASA2011I RRS INITIALIZATION COMPLETE. COMPONENT        |        
|           |     ID=SCRRS                                             |        
|           |                                                          |        
+-----------+----------------------------------------------------------+        
| --------  | If your system is busy, you may want to include a rule   |        
+-----------+ in your WLM policy that OMVS work for job ${zServerShortName}       |        
| Done:     | (such as the postinstaller step) is to run in a service  |        
|           | class with a high service objective.                     |        
| By:       |                                                          |        
+-----------+----------------------------------------------------------+        
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
| --------  | Start the Deployment Manager.                            |        
<!-- endif -->
<!-- if (${serverType}==JOB_MANAGER) --> 
| --------  | Start the Job Manager.                                   |        
<!-- endif -->
<!-- if (${serverType}==ADMIN_AGENT) --> 
| --------  | Start the Administrative Agent.                          |        
<!-- endif -->
+-----------+                                                          |        
| Done:     | Issue the MVS command                                    |        
|           |                                                          |        
|           |   START ${zControlProcName},JOBNAME=${zServerShortName},                       |        
|           |         ENV=${zCellShortName}.${zNodeShortName}.${zServerShortName}          |
|           |                                                          |        
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
| By:       | This command starts the deployment manager and also      |        
<!-- endif -->
<!-- if (${serverType}==JOB_MANAGER) --> 
| By:       | This command starts the job manager and also             |        
<!-- endif -->
<!-- if (${serverType}==ADMIN_AGENT) --> 
| By:       | This command starts the administrative agent and also    |        
<!-- endif -->
|           | starts the location service daemon. Wait until the       |        
|           | server is finished initializing before proceeding.       |        
|           |                                                          |        
|           | RESULT: The following message appears on the console and |        
|           | in the job log of ${zServerShortName}                    |        
|           |                                                          |        
|           |   BBOO0019I INITIALIZATION COMPLETE FOR WEBSPHERE FOR    |        
|           |     z/OS CONTROL PROCESS ${zServerShortName}             |        
|           |                                                          |        
+----------------------------------------------------------------------+        
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
| The deployment manager is now configured.                            |        
<!-- endif -->
<!-- if (${serverType}==JOB_MANAGER) --> 
| The job manager is now configured.                                   |        
<!-- endif -->
<!-- if (${serverType}==ADMIN_AGENT) --> 
| The adminstrative agent is now configured.                           |        
<!-- endif -->
|                                                                      |        
+-----------+----------------------------------------------------------+        
                                                                                                                                                              
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
Note: Once your deployment manager is up and running, you can expand            
the WebSphere Application Server cell by federating existing stand-             
alone servers, or by creating and federating new managed nodes.  Use            
the z/OS Profile Management Tool to perform these operations.                                                               
                                                                                                                                                                                                                                      
<!-- endif -->
+----------------------------------------------------------------------+        
<!-- if (${serverType}==DEPLOYMENT_MANAGER) --> 
| To start the deployment manager, issue the following MVS command:    |        
<!-- endif -->
<!-- if (${serverType}==JOB_MANAGER) --> 
| To start the job manager, issue the following MVS command:           |        
<!-- endif -->
<!-- if (${serverType}==ADMIN_AGENT) --> 
| To start the administrative agent, issue the following MVS command:  |        
<!-- endif -->
|                                                                      |        
|   START ${zControlProcName},JOBNAME=${zServerShortName},             |        
|         ENV=${zCellShortName}.${zNodeShortName}.${zServerShortName}  |
|                                                                      |
| To run this server in a reusable address space, add ",REUSASID=YES"  |
| to the end of the START command. See the article "Reusable address   |
| space" in the WebSphere Application Server for z/OS Information      |
| Center for more information, and important restrictions.             |
|                                                                      |        
| To stop the location service daemon and associated server(s), enter  |        
| the MVS command:                                                     |        
|                                                                      |        
|   STOP ${zDaemonJobName}                                             |        
|                                                                      |        
+----------------------------------------------------------------------+        

