Mainframe Path Start learning free
Applied10 min readLesson 1 of 3

SAF and the three security managers

z/OS products do not check security themselves. They ask SAF, which passes the question to the installed external security manager: RACF, ACF2 or Top Secret. The three answer the same questions with different models, and knowing those models makes you useful at any site.

One question, asked everywhere

Whenever a user logs on, a job opens a dataset or a CICS transaction starts, a component asks: *may this identity do this to this resource?* On z/OS that question goes to the System Authorization Facility (SAF), a router built into the operating system. SAF passes it to the external security manager (ESM) installed on the system and returns the answer.

How an access check flows
RequesterTSO, JES, CICS, DB2, MQ, USS
SAFRACROUTE interface
ESMRACF, ACF2 or Top Secret
Decisionallow, deny, log

Because everything goes through SAF, products like CICS, DB2 and MQ work with any of the three ESMs. Only one ESM is active on a system at a time.

The three ESMs

RACFACF2Top Secret
VendorIBMBroadcomBroadcom
User recordUser profile, connected to groupsLogonid recordACID (accessor ID)
Dataset protectionProfiles per dataset or generic patternAccess rules grouped by high-level qualifierResource ownership plus permissions to ACIDs or profiles
GroupingGroupsUID string built from logonid fieldsDepartments, divisions, zones and profile ACIDs
Undefined resourceDepends on options such as PROTECTALLDenied by defaultDenied by default (depending on mode)
Different thinking styles
RACF
Resource-centric profilesAccess lists name users and groupsUniversal access (UACC) as a fallbackGeneric profiles cover many names
ACF2
Rule-centricRule sets per HLQ say who may do whatProtection by defaultUID string matched against rules
Top Secret
Organisation-centricEverything is owned by a departmentProfiles group permissionsProtection by default in FAIL mode

You do not need to be expert in all three, but you should recognise them. Job adverts often name one, and the habits you learn in RACF (least privilege, groups or profiles instead of individuals, generic coverage) carry over directly.

Resource classes beyond datasets

Datasets are only part of the picture. ESMs also protect general resources: CICS transactions, DB2 objects, MQ queues, started tasks, operator commands, and sensitive system functions. In RACF these sit in classes such as FACILITY, OPERCMDS, SURROGAT, STARTED and many product-specific classes; ACF2 and Top Secret have equivalent resource types. Profiles in classes like FACILITY often guard powerful functions, so they deserve the same review as production datasets.

A RACF check, read as a sentenceWhat it means
PERMIT 'PAY.PROD.**'
For the generic dataset profile covering payroll production data
ID(PAYBATCH)
give the batch group or functional user
ACCESS(UPDATE)
the right to update, but not alter or delete the dataset

How SAF fits with z/OS UNIX

z/OS UNIX files have POSIX permission bits and optional ACLs, but identities still come from the ESM: the user's UID and GID live in the OMVS segment (RACF) or its equivalent. Superuser powers can come from UID 0 or from the BPX.SUPERUSER profile in the FACILITY class, which is safer because it is granted and audited explicitly.

Common mistakes

Thinking each product has its own passwords

CICS, DB2 and MQ normally rely on the ESM through SAF. A 'DB2 access problem' is often an ESM rule or profile.

Assuming all ESMs default the same way

ACF2 and Top Secret deny undefined resources by default; RACF behaviour depends on options. Know your site's setting before assuming.

Ignoring general resource classes

Powerful functions are guarded by profiles in classes like FACILITY and OPERCMDS. Review them as carefully as production datasets.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
Certificates, TLS and encryption →