WebSphere Application Server for z/OS V8.0 customization instructions:

Secure proxy administrative agent ${zServerShortName} (cell ${zCellShortName}, node ${zNodeShortName})
Tailored on ${ZDATE} at ${ZTIMEL} by ${ZUSER}
WCT version ${wctVersion} build ${wctBuild}

The management node will be configured with:

The Profile Management Tool has created a response file based on the information you provided. These instructions tell you how to convert this response file into a set of customization jobs and how to run the jobs to customize WebSphere Application Server for z/OS. When you upload the customization jobs to the target system, a text version of these instructions will be written to:

 
    ${zTargetHLQ}.CNTL(BBOCCINS)

Guidelines


Manual configuration updates

The Profile Management Tool does not attempt to update configuration data for your base operating system or existing subsystems. You need to perform the following manual steps prior to running the WebSphere for z/OS configuration jobs.



  1. Update BLSCUSER. To use the IPCS support provided by the product, append the following contents to the BLSCUSER member in your IPCSPARM or system PARMLIB dataset.
    
    

    Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the BLSCUSER member:

        ${zTargetHLQ}.CNTL(BBOIPCSP)
    





  2. Update SCHEDxx. To set the correct program properties for the WebSphere for z/OS run-time executables, append the following contents to the SCHEDxx member in your system PARMLIB concatenation.
    
    

    Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following paritioned data set member to the SCHEDxx member:

        ${zTargetHLQ}.CNTL(BBOSCHED)
    
    Note: When you are finished updating SCHEDxx, issue the command SET SCH=xx to activate SCHEDxx and load a new program properties table. This action does not need to be performed if the target z/OS system is at z/OS 1.9 or above, as the BPXBATA2 entry that the BBOSCHED member contains already exists in the IBM-supplied PPT table at those z/OS levels.




  3. Update SMFPRMxx. To collect the SMF120 records created by the run-time servers, update SMFPRMxx to include record type 120, as in the following example:

           SUBSYS(STC,EXITS(IEFU29,IEFACTRT),INTERVAL(SMF,SYNC),TYPE(0,30,70:79,88,89,120,245))
    


    For details on the SMF records, see related topics in the WebSphere for z/OS Information Center.







  4. Update your active BPXPRMxx member to have the following WebSphere Application Server for z/OS configuration file system:
    ${zConfigHfsName} mounted at: ${zConfigMountPoint} in read/write mode.

    Example:
    <!-- if (${zFilesystemType} == HFS) --> MOUNT FILESYSTEM('${zConfigHfsName}') MOUNTPOINT('${zConfigMountPoint}') TYPE(${zFilesystemType}) MODE(RDWR) NOAUTOMOVE <!-- endif --> <!-- if (${zFilesystemType} == ZFS) --> MOUNT FILESYSTEM('${zConfigHfsName}') MOUNTPOINT('${zConfigMountPoint}') TYPE(${zFilesystemType}) MODE(RDWR) PARM('AGGRGROW') NOAUTOMOVE <!-- endif --> Note: The NOAUTOMOVE parameter prevents the configuration file system from being mounted on a different z/OS system in a shared file system configuration, which could cause performance problems.

    If you have specified "aggrgrow=on" in your IOEFSPRM parmlib member, you can omit the AGGRGROW parm shown in the above examples



  5. Update TCP/IP by reserving the following ports for WebSphere Application Server for z/OS:

    Type Number
    SOAP JMX Connector port ${zSoapPort}
    ORB port ${zOrbListenerPort}
    Admin local port ${zAdminLocalPort}
    Daemon IP port ${zDaemonPort}
    Daemon SSL port ${zDaemonSslPort}

    Add the following contents to the PORT section of the TCP/IP profile that is used by the TCP/IP start procedure.

    
    

    Alternatively, once the customization jobs are uploaded to the target z/OS system, you may append the contents of the following partitioned data set member to the PORT section of the TCP/IP profile:

        ${zTargetHLQ}.CNTL(BBOTCPID)
    


    Attention: If another application has already reserved any of these ports for its own use, you must resolve the resulting conflict before you continue. If you use the Profile Management Tool to update the port specifications, be sure to upload the updated customization jobs.


    Note: It is recommended that the IPCONFIG, UDPCONFIG, and TCPCONFIG RESTRICTLOWPORTS be defined in your TCP/IP profile to only allow super users or APF-authorized user applications to bind to privileged ports (1-1024), unless the SAF keyword is specified and the user ID binding to the port is permitted to the SAF resource. It is left up to the users' discretion to determine whether this is viable course of action given the users' specific application/port requirements. For more information please consult: z/OS Communication Server IP Configuration Guide.





  6. WebSphere Application Server for z/OS customization assumes that the following system data sets are in the system link list: Language Environment SCEERUN SCEERUN2 System SSL SIEALNKE Support for 64-bit SCLBDLL2

    See the Language Environment Customization manual and the System SSL Programming manual for your z/OS release for advice on placing members from the libraries into the system link pack area.

    Placing these data sets in the link list insulates your WebSphere Application Server for z/OS configuration from changes in data set names (for example, when migrating to newer releases of z/OS).

    If the Language Environment or System SSL load module libraries are not in your system link list, you need to perform the following steps before starting any WebSphere Application Server for z/OS servers:


    If you regenerate server cataloged procedures at any point, make sure the data sets are added to the new cataloged procedures.








Running the customized jobs


The Profile Management Tool built a number of batch jobs with the variables you supplied. You need to run the jobs in the order listed below, using user IDs with the appropriate authority.

Before you begin: Complete the section above entitled "Manual configuration updates".

Follow the steps below, which lists in order the jobs you must submit and the commands you must enter. Special handling notes are included in the steps. All jobs are members of:
${zTargetHLQ}.CNTL

By default, the customization jobs below are all generated with REGION=0M. If this is not an allowable value on your target system, you may need to modify this value for your environment. Your system must allow a private region of sufficient size to allow the running of a Java Virtual Machine Region with a maximum heap specification of 256 Megabytes (i.e., -Xmx256m). Installation constraints that limit the region size or system exits that restrict the region a job is running in, may cause the customization jobs to fail due to a JVM error. In the event of an Out Of Memory (OOM) failure due to inadequate native storage, you must remove this constraint in order to successfully install WebSphere for z/OS.

Attention: After submitting each job, carefully check the output. Errors may exist even when all return codes are zero.

The BBOSBRAK and BBOSBRAM jobs do not need to be run if the indicated groups, user IDs and directories already exist with the correct gid, uid and ownership permission values, as given below.

In order for RACF to automatically select an unused UID or GID value for WebSphere Application Server user IDs and groups:

- The RACF profile SHARED.IDS must be defined.
- The RACF profile BPX.NEXT.USER must be define and use to indicate the ranges from which UID and GID values are to be selected.

See the article "Preparing the Security Server (RACF)" in the WebSphere Application Server for z/OS online information center. For more information, consult Chapter 20, "RACF and z/OS Unix", in the z/OS Security Server RACF Security Administrator's Guide (SA22-7683).

  1. Run job BBOSBRAK

    User ID requirement: RACF special authority.


    The commands are placed into member BBOSBRAK of data set
    ${zTargetHLQ}.DATA

    Carefully review these definitions with your security administrator.


    If the group and user IDs named above have already been created during a previous WebSphere Application Server for z/OS configuration and are in all target system RACF databases, you do not need to rerun this job.

    Note: This job creates the WebSphere administrator ID ${zAdminUserid} without a password (or password phrase). You must assign this user ID a password (or password phrase) that complies with your institution standards. This is also the password (or password phrase) that will be used when logging on to the WebSphere Application Server administrative console.

    Enter the following RACF command to assign a password:

    	ALTUSER ${zAdminUserid} PASSWORD(password) NOEXPIRED
    

    Enter the following RACF command to assign a password phrase:
    	ALTUSER ${zAdminUserid} PHRASE('password phrase') NOEXPIRED 
    

    If you are using a different security system, make sure that the ${zAdminUserid} has a password or password phrase.

    To use RACF password phrase support, your target system must be at z/OS Version 1.9 or above

    Result: You may receive errors, such as INVALID USER messages, from this job because a user ID, group or profile is already defined. Make sure the existing user ID, group, or profile has the same characteristics as the user ID, group, or profile being created by BBOSBRAK. If not, then change the values in the Profile Management Tool, which are causing the conflict. Then upload the updated customization jobs and restart the process.

    When this step is complete, all groups and user IDs listed above for job BBOSBRAK should be defined in the RACF database on each target system for the cell.

    Note: The WebSphere Application Server owner user ID ${zAdminUserid} must have the WebSphere Application Server configuration group ${zConfigurationGroup} as its default OMVS group.





  2. Run job BBOSBRAM



  3. Run job BBODBRAK

    User ID requirement: RACF special authority.


    This job executes the RACF commands to create RACF users and profiles required by this WebSphere for z/OS node.

    ${zTargetHLQ}.DATA(BBODBRAC)
    Carefully review these definitions with your security administrator.

    Result: You may receive errors, such as INVALID USER messages, from this job because a user ID, group or profile is already defined. Make sure the existing user ID, group or profile has the same characteristics as the user ID, group or profile being created by BBODBRAK. If not, then change the values in the Profile Management Tool which are causing the conflict, upload the updated customization jobs, and restart the process.





  4. Check user ID authorization
  5. Run job BBODCFS
  6. Run the BBODHFSA job
  7. Run the BBOWWPFD job



  8. Run the BBODPROC job




  9. All WebSphere Application Server processes require access to the Language Environment and System SSL load modules.
    If the SCEERUN, SCEERUN2 and System SSL load module libraries are not in the system link list, add them to the STEPLIB DD concatenation in each of the following cataloged procedures in ${zProclibName} : ${zControlProcName} ${zServantProcName} ${zDaemonProcName} and also add the full data set names, separated by colons (:), to the STEPLIB variable in the shell script
    ${zConfigMountPoint}/${zWasServerDir}/profiles/default/bin/setupCmdLine.sh               
    
    When modifying the setupCmdLine.sh script, do not remove lines or comment them out, as this may cause problems with automated updates to the script.
    Add only those data sets which are NOT in the link list.



  10. Make sure Resource Recovery Services (RRS) is active. (See the online information center for setup instructions if necessary.) Look for the following console message to verify that RRS was successfully started:
    ASA2011I RRS INITIALIZATION COMPLETE. COMPONENT ID=SCRRS


  11. Update WLM policy. If your system is busy, you may want to include a rule in your WLM policy that OMVS work for job ${zServerShortName} (such as the postinstaller step) is to run in a service class with a high service objective.



  12. Start the Administrative Agent
  13. The Administrative Agent is now configured

To stop the WebSphere Application Server for z/OS servers, enter the MVS command:
STOP ${zDaemonJobName}