The management node will be configured with:
The Profile Management Tool has created a response file based on the information you provided. These instructions tell you how to convert this response file into a set of customization jobs and how to run the jobs to customize WebSphere Application Server for z/OS. When you upload the customization jobs to the target system, a text version of these instructions will be written to:
${zTargetHLQ}.CNTL(BBOCCINS)
${zTargetHLQ}.CNTL
${zTargetHLQ}.DATA
Use the Process action to create the customization jobs and upload them to the target z/OS system.
The Profile Management Tool does not attempt to update configuration data for your base operating system or existing subsystems. You need to perform the following manual steps prior to running the WebSphere for z/OS configuration jobs.
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the BLSCUSER member:
${zTargetHLQ}.CNTL(BBOIPCSP)
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following paritioned data set member to the SCHEDxx member:
${zTargetHLQ}.CNTL(BBOSCHED)
Note: When you are finished updating SCHEDxx, issue the command
SET SCH=xx to activate SCHEDxx and load a new program properties
table. This action does not need to be performed if the target z/OS system is
at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED member contains
already exists in the IBM-supplied PPT table at those z/OS levels.
SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),TYPE(0,30,70:79,88,89,120,245))
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zSoapPort} |
| Cell Discovery Address port | ${zCellDiscoveryPort} |
| ORB port | ${zOrbListenerPort} |
| ORB SSL port | ${zOrbListenerSslPort} |
| Administrative console port | ${zAdminConsolePort} |
| Administrative console secure port | ${zAdminConsoleSecurePort} |
| Admin local port | ${zAdminLocalPort} |
| High Availability Manager Communication port | ${zHighAvailManagerPort} |
| Daemon IP port | ${zDaemonPort} |
| Daemon SSL port | ${zDaemonSslPort} |
Add the following contents to the PORT section of the TCP/IP profile that is used by the TCP/IP start procedure.
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the PORT section of the TCP/IP profile:
${zTargetHLQ}.CNTL(BBOTCPID)
Attention: If another application has already reserved any of these ports for its own use, you must resolve the resulting conflict before you continue. If you use the Profile Management Tool to update the port specifications, be sure to upload the updated customization jobs.
Note: It is recommended that the IPCONFIG, UDPCONFIG, and TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to only allow super users or APF-authorized user applications to bind to privileged ports (1-1024), unless the SAF keyword is specified and the user ID binding to the port is permitted to the SAF resource. It is left up to the users' discretion to determine whether this is viable course of action given the users' specific application/port requirements. For more information please consult: z/OS Communication Server IP Configuration Guide.
See the Language Environment Customization manual and the System SSL Programming manual for your z/OS release for advice on placing members from the libraries into the system link pack area.
Placing these data sets in the link list insulates your WebSphere Application Server for z/OS configuration from changes in data set names (for example, when migrating to newer releases of z/OS).
If the Language Environment or System SSL load module libraries are not in your system link list, you need to perform the following steps before starting any WebSphere Application Server for z/OS servers:
The Profile Management Tool built a number of batch jobs with the variables you supplied. You need to run the jobs in the order listed below, using user IDs with the appropriate authority.
Before you begin: Complete the section above entitled "Manual configuration updates".
| Type | Group/userid | GID/UID |
|---|---|---|
| Administrator user ID | ${zAdminUserid} | ${zAdminUid} |
| Control user ID | ${zControlUserid} | ${zControlUid} |
| Servant user ID | ${zServantUserid} | ${zServantUid} |
| Configuration group | ${zConfigurationGroup} | ${zConfigurationGroupGID} |
| Servant group | ${zServantGroup} | ${zServantGroupGID} |
| Local user group | ${zLocalUserGroup} | ${zLocalUserGroupGID} |
Carefully review these definitions with your security administrator.
ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED
ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED
Result: You may receive errors, such as INVALID USER messages, from this job because a user ID, group or profile is already defined. Make sure the existing user ID, group, or profile has the same characteristics as the user ID, group, or profile being created by BBOSBRAK. If not, then change the values in the Profile Management Tool, which are causing the conflict. Then upload the updated customization jobs and restart the process.
When this step is complete, all groups and user IDs
listed above for job BBOSBRAK should be defined in the
RACF database on each target system for the cell.
Note: The WebSphere Application Server administrator user ID
${zAdminUserid} must have the WebSphere Application Server
configuration group ${zConfigurationGroup} as its
default OMVS group.
User ID requirement: File system update authority (see above).
This job creates home directories for WebSphere Application Server for z/OS user IDS. These home directories will be subdirectories of ${zUserIDHomeDirectory}
This job will create the following directories:
${zUserIDHomeDirectory}
ownership: (any)
permission bits: 755
${zUserIDHomeDirectory}/${zConfigurationGroup}
ownership: ${zControlUserid}:${zConfigurationGroup}
permission bits: 770
${zUserIDHomeDirectory}/${zServantGroup}
ownership: ${zControlUserid}:${zServantGroup}
permission bits: 770
${zUserIDHomeDirectory}/${zLocalUserGroup}
ownership: ${zControlUserid}:${zLocalUserGroup}
permission bits: 770
This job should be run on each z/OS system that will host WebSphere Application Server nodes using these WebSphere Application Server for z/OS common groups and owner user ID. After execution, verify that the directories have been created with the correct permissions on each system.
If these directories already exist with the specified ownership and permission on a target system, then this job does not need to be run on that system.
Attention: If the directory ${zUserIDHomeDirectory} is used by applications other than WebSphere Application Server, make sure that the permissions set by BBOSBRAM (755) are appropriate, or change them manually. This directory must be world-readable for Websphere Application Server to run correctly.
This job executes the RACF commands to create RACF users and profiles required
by this WebSphere for z/OS node.
These commands are located in
| Type | Userid | UID |
|---|
| Type | Userid | UID |
|---|---|---|
| Unauthenticated user ID | ${zAdminUnauthenticatedUserid} | ${zAdminUnauthenticatedUid} |
| Daemon user ID | ${zDaemonUserid} | ${zDaemonUid} |
Carefully review these definitions with your security administrator.
Result: You may receive errors, such as INVALID USER
messages, from this job because a user ID, group or
profile is already defined. Make sure the existing
user ID, group or profile has the same characteristics
as the user ID, group or profile being created by
BBODBRAK. If not, then change the values in the
Profile Management Tool which are causing the conflict,
upload the updated customization jobs, and restart the process.
${zControlUserid}
${zDaemonUserid}
cd ${zConfigMountPoint}/${zWasServerDir}
./bin/manageprofiles.sh -deleteAll
rm -R profiles
Then correct the problem that caused BBOWWPFD to fail and re-run the job.
${zConfigMountPoint}/${zWasServerDir}/profiles/default/bin/setupCmdLine.sh
When modifying the setupCmdLine.sh script, do not
remove lines or comment them out, as this may cause
problems with automated updates to the script.