Resource Access Control Facility (RACF) is an IBM software security product that provides access control and auditing functions for the z/OS and z/VMoperating systems.[1] RACF was introduced in 1976.[2] Originally called RACF it was renamed to z/OS Security Server (RACF), although many mainframe professionals still refer to it as RACF.[3]
Its main features are:[2]
RACF establishes security policies rather than just permission records. It can set permissions for file patterns—that is, set the permissions even for files that do not yet exist. Those permissions are then used for the file (or other object) created at a later time.[4]
There is a long established technical support community for RACF based around a LISTSERV operated out of the University of Georgia. The list is called RACF-L which is described as RACF Discussion List. The email address of the listserv is RACF-L@LISTSERV.UGA.EDU and can also be viewed via a webportal at https://listserv.uga.edu/scripts/wa-UGA.exe .[5][6]
The first text book published (first printing December 2007) aimed at giving security professionals an introduction to the concepts and conventions of how RACF is designed and administered was Mainframe Basics for Security Professionals: Getting Started with RACF by Ori Pomerantz, Barbara Vander Weele, Mark Nelson, and Tim Hahn.[4]
RACF は、デジタル証明書/公開鍵基盤サービス、LDAPインターフェース、大文字小文字を区別する ID/パスワードなどの最新のセキュリティ機能をサポートするために継続的に進化してきました[ 7 ]。後者は、UnixやLinuxなどの他のシステムとの相互運用性を促進するための不本意な譲歩です。基盤となるzSeries (現在のIBM Z ) ハードウェアは RACF と密接に連携しています。たとえば、デジタル証明書は改ざん防止暗号プロセッサ内で保護されています。主要なメインフレームサブシステム、特にDb2 は、RACF を使用してマルチレベルセキュリティ(MLS) を提供しています。
{{cite book}}: CS1 maint: 数値名: 著者リスト (リンク)