The deployment manager and application server nodes will be configured with:
The Profile Management Tool has created a response file based on the information you provided. These instructions tell you how to convert this response file into a set of customization jobs and how to run the jobs to customize WebSphere Application Server for z/OS. When you upload the customization jobs to the target system, a text version of these instructions will be written to:
${zTargetHLQ}.CNTL(BBODMINS)
${zTargetHLQ}.CNTL
${zTargetHLQ}.DATA
Use the Process action to create the customization jobs and upload them to the target z/OS system.
The Profile Management Tool does not attempt to update configuration data for your base operating system or existing subsystems. You need to perform the following manual steps prior to running the WebSphere for z/OS configuration jobs.
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the BLSCUSER member:
${zTargetHLQ}.CNTL(BBOIPCSP)
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following paritioned data set member to the SCHEDxx member:
${zTargetHLQ}.CNTL(BBOSCHED)
Note: When you are finished updating SCHEDxx, issue the command
SET SCH=xx to activate SCHEDxx and load a new program properties
table. This action does not need to be performed if the target z/OS system is
at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED member contains
already exists in the IBM-supplied PPT table at those z/OS levels.
SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),TYPE(0,30,70:79,88,89,120,245))
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zSoapPort} |
| Cell Discovery Address port | ${zCellDiscoveryPort} |
| ORB port | ${zOrbListenerPort} |
| ORB SSL port | ${zOrbListenerSslPort} |
| Administrative console port | ${zAdminConsolePort} |
| Administrative console secure port | ${zAdminConsoleSecurePort} |
| Admin local port | ${zAdminLocalPort} |
| High Availability Manager Communications port | ${zHighAvailManagerPort} |
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zNodeAgentJmxSoapConnectorPort} |
| Node Discovery port | ${zNodeAgentNodeDiscoveryPort} |
| Node Multicast Discovery Port | ${zNodeAgentNodeMulticastDiscoveryPort} |
| Node IPv6 multicast discovery port | ${zNodeAgentNodeIPv6MulticastDiscoveryPort} |
| ORB port | ${zNodeAgentOrbPortName} |
| Admin local port | ${zNodeAgentAdminLocalPort} |
| High Availability Manager Communication port | ${zNodeAgentHamCommPort} |
| ORB SSL port | ${zNodeAgentOrbSslPortName} |
| Type | Number |
|---|---|
| SOAP JMX Connector port | ${zAppServerSoapPort} |
| ORB port | ${zAppServerOrbListenerPort} |
| ORB SSL port | ${zAppServerOrbListenerSslPort} |
| Admin local port | ${zAppServerAdminLocalPort} |
| High availability manager communication port | ${zAppServerOrbListenerSslPort} |
| Service Integration port | ${zAppServerServiceIntegrationPort} |
| Service Integration Secure port | ${zAppServerServiceIntegrationSecurePort} |
| Service Integration MQ Interoperability port | ${zAppServerServiceIntegrationMqPort} |
| Service Integration MQ Interoperability Secure port | ${zAppServerServiceIntegrationSecureMqPort} |
| Session Initiation Protocol (SIP) port | ${zAppServerSessionInitiationPort} |
| Session Initiation Protocol (SIP) secure port | ${zAppServerSessionInitiationSecurePort} |
| Type | Number |
|---|---|
| Daemon IP port | ${zDaemonPort} |
| Daemon SSL port | ${zDaemonSslPort} |
Add the following contents to the PORT section of the TCP/IP profile that is used by the TCP/IP start procedure.
Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the PORT section of the TCP/IP profile:
${zTargetHLQ}.CNTL(BBOTCPIC)
Attention: If another application has already reserved any of these ports for its own use, you must resolve the resulting conflict before you continue. If you use the Profile Management Tool to update the port specifications, be sure to upload the updated customization jobs.
Note: It is recommended that the IPCONFIG, UDPCONFIG, and TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to only allow super users or APF-authorized user applications to bind to privileged ports (1-1024), unless the SAF keyword is specified and the user ID binding to the port is permitted to the SAF resource. It is left up to the users' discretion to determine whether this is viable course of action given the users' specific application/port requirements. For more information please consult: z/OS Communication Server IP Configuration Guide.
See the Language Environment Customization manual and the System SSL Programming manual for your z/OS release for advice on placing members from the libraries into the system link pack area.
Placing these data sets in the link list insulates your WebSphere Application Server for z/OS configuration from changes in data set names (for example, when migrating to newer releases of z/OS).
If the Language Environment or System SSL load module libraries are not in your system link list, you need to perform the following steps before starting any WebSphere Application Server for z/OS servers:
The Profile Management Tool built a number of batch jobs with the variables you supplied. You need to run the jobs in the order listed below, using user IDs with the appropriate authority.
Before you begin: Complete the section above entitled "Manual configuration updates".
| Type | Group/userid | GID/UID |
|---|---|---|
| Administrator user ID | ${zAdminUserid} | ${zAdminUid} |
| Control user ID | ${zControlUserid} | ${zControlUid} |
| Servant user ID | ${zServantUserid} | ${zServantUid} |
| Configuration group | ${zConfigurationGroup} | ${zConfigurationGroupGID} |
| Servant group | ${zServantGroup} | ${zServantGroupGID} |
| Local user group | ${zLocalUserGroup} | ${zLocalUserGroupGID} |
Carefully review these definitions with your security administrator.
ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED
ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED
Result: You may receive errors, such as INVALID USER messages, from this job because a user ID, group or profile is already defined. Make sure the existing user ID, group, or profile has the same characteristics as the user ID, group, or profile being created by BBOSBRAK. If not, then change the values in the Profile Management Tool, which are causing the conflict. Then upload the updated customization jobs and restart the process.
When this step is complete, all groups and user IDs
listed above for job BBOSBRAK should be defined in the
RACF database on each target system for the cell.
Note: The WebSphere Application Server administrator user ID
${zAdminUserid} must have the WebSphere Application Server
configuration group ${zConfigurationGroup} as its
default OMVS group.
User ID requirement: File system update authority (see above).
This job creates home directories for WebSphere Application Server for z/OS user IDS. These home directories will be subdirectories of ${zUserIDHomeDirectory}
This job will create the following directories:
${zUserIDHomeDirectory}
ownership: (any)
permission bits: 755
${zUserIDHomeDirectory}/${zConfigurationGroup}
ownership: ${zControlUserid}:${zConfigurationGroup}
permission bits: 770
${zUserIDHomeDirectory}/${zServantGroup}
ownership: ${zControlUserid}:${zServantGroup}
permission bits: 770
${zUserIDHomeDirectory}/${zLocalUserGroup}
ownership: ${zControlUserid}:${zLocalUserGroup}
permission bits: 770
This job should be run on each z/OS system that will host WebSphere Application Server nodes using these WebSphere Application Server for z/OS common groups and owner user ID. After execution, verify that the directories have been created with the correct permissions on each system.
If these directories already exist with the specified ownership and permission on a target system, then this job does not need to be run on that system.
Attention: If the directory ${zUserIDHomeDirectory} is used by applications other than WebSphere Application Server, make sure that the permissions set by BBOSBRAM (755) are appropriate, or change them manually. This directory must be world-readable for Websphere Application Server to run correctly.
This job executes the RACF commands to create RACF users and profiles required
by this WebSphere for z/OS cell.
These commands are located in
Carefully review these definitions with your security administrator.
Result: You may receive errors, such as INVALID USER
messages, from this job because a user ID, group or
profile is already defined. Make sure the existing
user ID, group or profile has the same characteristics
as the user ID, group or profile being created by
BBODBRAK. If not, then change the values in the
Profile Management Tool which are causing the conflict,
upload the updated customization jobs, and restart the process.
This job executes the RACF commands to create RACF users and profiles required
by this WebSphere for z/OS cell.
These commands are located in
| Type | Userid | UID |
|---|---|---|
| Asynch admin user ID | ${zAdminAsynchTaskUserid} | ${zAdminAsynchTaskUid} |
| Unauthenticated user ID | ${zAdminUnauthenticatedUserid} | ${zAdminUnauthenticatedUid} |
| Daemon user ID | ${zDaemonUserid} | ${zDaemonUid} |
| Adjunct user ID | ${zAdjunctUserid} | ${zAdjunctUid} |
Carefully review these definitions with your security administrator.
Result: You may receive errors, such as INVALID USER
messages, from this job because a user ID, group or
profile is already defined. Make sure the existing
user ID, group or profile has the same characteristics
as the user ID, group or profile being created by
BBOCBRAK. If not, then change the values in the
Profile Management Tool which are causing the conflict,
upload the updated customization jobs, and restart the process.
Make sure the ${zConfigurationGroup} group has read access to all WebSphere product data sets, as well as to any other data sets which will be placed in WebSphere Application Server for z/OS cataloged procedure STEPLIB concatenations.
Make sure the following user IDs have read access to
the resolver configuration file in use on your system.
Depending on your IP setup, this file may be
/etc/resolv.conf, SYS1.TCPPARMS(TCPDATA), or another
data set.
See the z/OS eNetwork Communication Server IP Configuration manual for the resolver search order.
Ensure the following user ID has read access to the data
sets in your system parmlib concatenation:
Attention: If operator commands are protected by the z/OS security server at your installation, you must ensure that sufficient authority is given to WebSphere tasks to control operations.
The Deployment Manager and Application Server controller user ID (${zControlUserid}) needs the ability to perform operations on started tasks belonging to WebSphere Application Server for z/OS.
The asynchronous administrator user ID, and any user ID used to run the federation job when the node agent is started automatically, need the authority to issue the MVS START command.
If you are currently controlling MVS console command
authority with SAF OPERCMDS profiles, grant the
following authorities as indicated, substituting your
own profile names:
You need to also grant the appropriate console command authority to any user ID that executes the startServer.sh or stopServer.sh script.
Before running this job: Verify that the DD statements which define
the data sets are valid for the storage rules defined on the target system.
This job:
Creates the following mount point directories
Allocates the following configuration file system(s) using the Hierarchical File System (HFS)
${zConfigHfsName}
${zAppServerConfigHfsName}
Allocates the following configuration file system(s) using the z/OS Distributed File Service zSeries File System (zFS)
${zConfigHfsName}
${zAppServerConfigHfsName}
Allocates the following configuration file system using the Hierarchical File System (HFS) ${zAppServerConfigHfsName}
Allocates the following configuration file system
using the z/OS Distributed File Service zSeries File
System (zFS)
${zAppServerConfigHfsName}
and mounts them at the above mount points.
cd ${zConfigMountPoint}/${zWasServerDir}
./bin/manageprofiles.sh -deleteAll
rm -R profiles
cd ${zAppServerConfigMountPoint}/${zAppServerWasServerDir}
./bin/manageprofiles.sh -deleteAll
rm -R profiles
Then correct the problem that caused BBOWWPFC to fail and re-run the job.
The WebSphere Application Server has been configured to use the IBM SDK for Java 6 with 64-bit addressing. Refer to the WebSphere Application Server for z/OS Information Center for a list of the available IBM SDKs for Java and directions on how to configure a different one.
${zConfigMountPoint}/${zWasServerDir}/profiles/default/bin/setupCmdLine.sh
${zAppServerConfigMountPoint}/${zAppServerWasServerDir}/profiles/default/bin/setupCmdLine.sh
When modifying the setupCmdLine.sh script, do not
remove lines or comment them out, as this may cause
problems with automated updates to the script.