SAF and the three security managers
z/OS products do not check security themselves. They ask SAF, which passes the question to the installed external security manager: RACF, ACF2 or Top Secret. The three answer the same questions with different models, and knowing those models makes you useful at any site.
One question, asked everywhere
Whenever a user logs on, a job opens a dataset or a CICS transaction starts, a component asks: *may this identity do this to this resource?* On z/OS that question goes to the System Authorization Facility (SAF), a router built into the operating system. SAF passes it to the external security manager (ESM) installed on the system and returns the answer.
Because everything goes through SAF, products like CICS, DB2 and MQ work with any of the three ESMs. Only one ESM is active on a system at a time.
The three ESMs
| RACF | ACF2 | Top Secret | |
|---|---|---|---|
| Vendor | IBM | Broadcom | Broadcom |
| User record | User profile, connected to groups | Logonid record | ACID (accessor ID) |
| Dataset protection | Profiles per dataset or generic pattern | Access rules grouped by high-level qualifier | Resource ownership plus permissions to ACIDs or profiles |
| Grouping | Groups | UID string built from logonid fields | Departments, divisions, zones and profile ACIDs |
| Undefined resource | Depends on options such as PROTECTALL | Denied by default | Denied by default (depending on mode) |
You do not need to be expert in all three, but you should recognise them. Job adverts often name one, and the habits you learn in RACF (least privilege, groups or profiles instead of individuals, generic coverage) carry over directly.
Resource classes beyond datasets
Datasets are only part of the picture. ESMs also protect general resources: CICS transactions, DB2 objects, MQ queues, started tasks, operator commands, and sensitive system functions. In RACF these sit in classes such as FACILITY, OPERCMDS, SURROGAT, STARTED and many product-specific classes; ACF2 and Top Secret have equivalent resource types. Profiles in classes like FACILITY often guard powerful functions, so they deserve the same review as production datasets.
PERMIT 'PAY.PROD.**'ID(PAYBATCH)ACCESS(UPDATE)How SAF fits with z/OS UNIX
z/OS UNIX files have POSIX permission bits and optional ACLs, but identities still come from the ESM: the user's UID and GID live in the OMVS segment (RACF) or its equivalent. Superuser powers can come from UID 0 or from the BPX.SUPERUSER profile in the FACILITY class, which is safer because it is granted and audited explicitly.
Common mistakes
CICS, DB2 and MQ normally rely on the ESM through SAF. A 'DB2 access problem' is often an ESM rule or profile.
ACF2 and Top Secret deny undefined resources by default; RACF behaviour depends on options. Know your site's setting before assuming.
Powerful functions are guarded by profiles in classes like FACILITY and OPERCMDS. Review them as carefully as production datasets.
What you will see at work
- Security teams translate access requests into the site's ESM language: profiles and permits, rules, or ACID permissions.
- When an access fails, the first job is to find which class and resource the ESM actually checked.
- Migration and merger projects map rules between ESMs, which needs people who understand more than one model.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.