Mfe Getting Started
Mfe Getting Started
1. Table of Contents
4.3.1.5. AUTHVFY............................................................................................................................................................................. 18
• FAILMSG/FMSG ............................................................................................................................................................................. 19
• TOKENDISP/TKND ...................................................................................................................................................................... 19
• WARN ................................................................................................................................................................................................. 19
• START/STOP DATE - SDT/EDT(yymmdd) ...................................................................................................................... 19
• START/STOP TIME - STM/ETM(hhmm)........................................................................................................................... 19
4.3.1.6. CERTVFY.............................................................................................................................................................................. 19
4.3.2. CATEGORY .END ........................................................................................................................................................ 19
4.4. NSEENSXX ..........................................................................................................................................................................20
4.4.1. ACTION MFEPERMT(userid) METHOD(parm) ............................................................................................ 20
4.4.1.1. TO (permitted user’s email address) ..................................................................................................................... 20
4.4.1.2. 3RDPARTY .......................................................................................................................................................................... 20
4.4.1.3. FROM (permitted user’s email address) .............................................................................................................. 20
4.4.1.4. START/STOP DATE - SDT/EDT(yymmdd) ......................................................................................................... 20
4.4.1.5. START/STOP TIME - STM/ETM(hhmm) ............................................................................................................. 20
4.4.1.6. MFEPREFIX ........................................................................................................................................................................ 21
4.4.1.7. WHEN MFECATEGORY(category_name) ............................................................................................................. 21
4.4.2. ACTION .END .............................................................................................................................................................. 21
4.4.3. ACTION MFECAT(category_name) ................................................................................................................... 21
4.4.3.1. TO (as many as necessary) ......................................................................................................................................... 21
4.4.3.2. FROM ..................................................................................................................................................................................... 21
4.4.3.3. SUBJECT ............................................................................................................................................................................... 21
4.4.4. ACTION .END .............................................................................................................................................................. 21
4.4.5. ACTION MFEAUD(category_name) ................................................................................................................... 21
4.4.5.1. TO (as many as necessary) ......................................................................................................................................... 21
4.4.5.2. FROM ..................................................................................................................................................................................... 21
4.4.5.3. SUBJECT ............................................................................................................................................................................... 21
4.4.6. ACTION .END .............................................................................................................................................................. 21
4.4.7. ACTION MFEAMDAY/WKS/MTH(userid) ...................................................................................................... 22
4.4.7.1. TO (as many as necessary) ......................................................................................................................................... 22
4.4.7.2. FROM ..................................................................................................................................................................................... 22
4.4.7.3. SUBJECT ............................................................................................................................................................................... 22
4.4.8. ACTION .END .............................................................................................................................................................. 22
4.4.9. ACTION MFEAUDAY/WKS/MTH(userid) ....................................................................................................... 22
4.4.9.1. TO (as many as necessary) ......................................................................................................................................... 22
4.4.9.2. FROM ..................................................................................................................................................................................... 22
4.4.9.3. SUBJECT ............................................................................................................................................................................... 22
4.4.10. ACTION .END ........................................................................................................................................................ 22
4.4.11. ACTION PSWDEXP(USERID) METHOD(EMAIL) SCOPE(REPORT) ............................................... 22
4.4.11.1. TO............................................................................................................................................................................................ 22
4.4.11.2. ALIAS ..................................................................................................................................................................................... 22
4.4.11.3. INTERVAL (0,1,2,3,4,5,15,30) ................................................................................................................................... 22
4.4.11.4. SUBJECT 'EXPIRE NOTIFICATION' ......................................................................................................................... 23
4.4.11.5. FROM ..................................................................................................................................................................................... 23
4.4.12. ACTION .END ........................................................................................................................................................ 23
4.5. NSEDETXX ..........................................................................................................................................................................24
4.5.1. MFEDETECDAY/WKS/MTH ON|OFF ............................................................................................................... 24
4.5.2. MFEDETAMDAY/WKS/MTH ON|OFF .............................................................................................................. 24
4.5.2.1. CYCLE(DAILY) TIME(hh:mm) INTERVAL(1 - 12) ........................................................................................... 24
4.5.2.2. CYCLE(WEEKLY(MON,TUE,WED,THR,FRI,SAT,SUN)) TIME(hh:mm) .................................................. 24
4.5.2.3. CYCLE(MONTHLY(DOM(day_number)EOM)) TIME(hh:mm) ................................................................... 24
5. MFE PANEL INTERFACE .............................................................................................................................25
5.1. THE MFE PRIMARY CATEGORY DIALOG ........................................................................................................................25
5.2. ACCESS VIA THE TSO/ISPF COMMAND LINE ..............................................................................................................26
5.3. DIALOG FUNCTIONAL DESCRIPTION................................................................................................................................26
5.3.1. Text shown in the ‘Mfe’ Column indicates Category State ...................................................................... 27
• ‘---' ........................................................................................................................................................................................................ 27
• ‘(v)’....................................................................................................................................................................................................... 27
• ‘(c)’ ....................................................................................................................................................................................................... 27
• ‘(b)’ ...................................................................................................................................................................................................... 27
5.3.2. To Create or Update an MFE Category Profile ............................................................................................. 27
5.3.3. To Permit or Update User Permissions to a Category Profile ................................................................ 27
5.3.4. Switching to Reporting Mode .............................................................................................................................. 27
5.4. CONFIGURING MFE CATEGORY PROFILES FOR VERIFICATION ..................................................................................28
5.4.1. Inserting an AUTHVFY Control Card ................................................................................................................ 28
5.4.1.1. FailMsg ................................................................................................................................................................................. 28
5.4.1.2. TokenDisp ........................................................................................................................................................................... 28
5.4.1.3. StartDate.............................................................................................................................................................................. 28
5.4.1.4. StartTime............................................................................................................................................................................. 28
5.4.1.5. StopDate .............................................................................................................................................................................. 28
5.4.1.6. StopTime ............................................................................................................................................................................. 29
5.4.2. Updating, Removing a Profile .............................................................................................................................. 29
5.4.2.1. ‘S’ ............................................................................................................................................................................................. 29
5.4.2.2. ‘R‘............................................................................................................................................................................................. 29
5.5. MFE PROFILED CATEGORIES – ISPF WORKSHEET AND REPORT ............................................................................29
5.5.1. Column Headings ...................................................................................................................................................... 30
5.5.2. Row Commands ......................................................................................................................................................... 30
5.6. PERMITTING USER TO MFE CATEGORY PROFILES.......................................................................................................31
5.6.1. Selecting a Permitted UserId ............................................................................................................................... 31
5.6.2. Permitting a New UserId ....................................................................................................................................... 31
5.7. DEFINING THE USERS PERMIT PROFILE AND PERMISSIONS.......................................................................................32
5.7.1. Delivery ......................................................................................................................................................................... 32
5.7.2. Permit ............................................................................................................................................................................ 32
5.7.3. Designee ........................................................................................................................................................................ 32
5.7.4. Permits .......................................................................................................................................................................... 32
5.7.5. Updates.......................................................................................................................................................................... 33
5.8. ALL PERMITTED USERS – ISPF WORKSHEET AND REPORT ......................................................................................33
5.8.1. Column Headings ...................................................................................................................................................... 33
5.8.2. Row Commands ......................................................................................................................................................... 33
5.9. CONFIGURING MFE CATEGORY PROFILES FOR CERTIFICATION................................................................................34
5.9.1. All Isolated Resources – ISPF Worksheet and Report ............................................................................... 34
5.9.1. Isolated .......................................................................................................................................................................... 34
5.10. NOTIFICATION/ALERTS OF MFE EVENTS AND ACTIONS ...........................................................................................34
5.10.1. MFE Alerts Report on These Events ............................................................................................................ 35
5.10.1.1. <ALLOW> ............................................................................................................................................................................ 35
5.10.1.2. <WARNS>............................................................................................................................................................................ 35
5.10.1.3. <FAILS> ................................................................................................................................................................................ 35
5.10.1.4. <3PART>.............................................................................................................................................................................. 35
5.10.1.5. MFE Notification Alerts Contain .............................................................................................................................. 35
5.10.1.6. Adding/Removing a Recipient .................................................................................................................................. 35
5.11. VIEWING ON-LINE MFE LOGS AND ACTIVITY REPORTS ............................................................................................36
5.11.1. Profile Log .............................................................................................................................................................. 36
5.11.1.1. Column Headings ............................................................................................................................................................ 36
5.11.1.2. Row Commands ............................................................................................................................................................... 37
5.11.2. Permit Log.............................................................................................................................................................. 38
5.11.2.1. Column Heading............................................................................................................................................................... 38
5.11.2.2. Row Commands ............................................................................................................................................................... 38
5.12. ADHOC TCE/MFE JOURNAL QUERY..............................................................................................................................39
5.12.1.1. ALLOW.................................................................................................................................................................................. 39
5.12.1.2. WARNS ................................................................................................................................................................................. 39
5.12.1.3. DENYS ................................................................................................................................................................................... 39
5.12.1.4. SETUP ................................................................................................................................................................................... 39
5.12.1.5. 3PART ................................................................................................................................................................................... 39
5.12.2. EventClass Sample .............................................................................................................................................. 40
This Token is valid for 2 minutes from the time of issuance. When resource access is
attempted, the user’s workflow is interrupted by a panel containing a Token Input Field. If the
Token is entered correctly into the field within the time limit, access is allowed and the
resource is displayed in ISPF Edit. If the Token is mis-entered or times out, access will be
denied. Any attempt to gain access following a denial or successful attempt begins the process
anew.
goes to the designee, its use is bound to the initiating user and only that user may use the
Token. As an added “Outside-The-System” control, a challenge conversation/dialog between
the user and the recipient designee could be added to create yet another Factor before the
Token value is revealed. If the Token is mis-entered or times out the access will be denied.
Any attempt to gain access following a denial or successful attempt would begin the process
anew.
Journal but in this case as an EXCEPTION, ISOLATED and NOT, as a New Version. These
Exception Records are used only for analytic and reporting purposes. Such Exceptions will
remain in their isolated state until they, as is the case with On-Access events, are
RECERTIFIED as VALID working copies. When an action is taken to RECERTIFY, a copy
of the known resource will be written anew to the Control Journal becoming the most recent
version to be useable as a Restore and Compare Point.
2.4.1. Browse
Display the Target in ISPF Browse.
2.4.2. Restore
Extract last Journal copy of Target and Restore it over the Actual Target. If this option is
taken, the restored copy is considered a Recertified version.
2.4.3. Accept
Use the Target "as is" Un-Certified.
2.4.4. Compare
Display a Target specific HISTLIST Compare Options.
2.4.5. Return
Exit/PFK3 back to the Member List
MFE use of the Token Generator and the resulting generated PASSTICKET is totally
dependent on the ESM permission and the generator’s underlying “KeyMask”. The following
command sequence shows the setup steps required to permit the ICE Primary Started Task,
IFOM access to the Token Generator and define the keymask for IBM RACF:
Once these steps are completed MFE will automatically cause Tokens to be generated for
exclusive use as One-Time Access Tokens. The “KeyMask” may be changed and refreshed
at any time without impacting its use by IFOM or any other Task that may be permitted to its
use.
3.3.2. WORKATTR/WAEMAIL
MFE supports WAEMAIL lookup, that is, when a UserId is provided by MFE, the ESM will
return the user’s stored Email Address, or not, if the address is unknown. Reverse lookup is
also supported, such that when MFE provides an Email Address the ESM will return the
UserId if the address is stored, or not if the address is unknown.
This optional Policy Decision Point is primarily used to validate Token Delivery Email
Addresses and is activated by adding this single Control Card to the ICE NSEJRNxx ParmLib
Member:
WAEMAILONLY YES
The lookup and reverse lookup capabilities of MFE may also be used in Interval Reporting of
changes in the WAEMAIL profiles being maintained by the External Security Manager.
In addition, all such alerts are written to the TCE Control Journal using the following
journal tags:
<ALLOW> - Resource access was allowed.
<WARNS> - User was warned of access failure but allowed because in Warn Mode.
<FAILS> - User notified of access failure and denied resource access.
<3PART> - Designee notified of in process access attempt.
<SETUP> - MFE Operation experienced setting problem.
These journal tags allow for real-time queries of MFE related events; on-line from TSO/ISPF
or at defined intervals for ADMIN and AUDIT Reporting.
While a number of default canned reports are generated on demand, AdHoc reports can be
created by entering the following command string on the TSO/ISPF Command Line.
TSO $CLI,*MYQRY
This command sequence will display the TCE ADHOC Query & Display panel shown here:
◊——————————————— Function - TCE ADHOC Query & Display ————————————————◊
◊ ICE 16.0 MY - TCE Journalled Events ◊
◊ ◊
◊ ---------------- Set the Data Characterization Profile ---------- ◊
◊ by Category .. or by EventClass .. ◊
◊ --------------------- Set the Journal Query Range --------------- ◊
◊ Begins with .. YY MM DD & Ends with .. YY MM DD ◊
◊ ---------------------- Check Presentation Format ----- .. NewOnly ◊
◊ .. Active-Matrix .. In-Summary .. MetaDetail .. FullDetail ◊
◊ ◊
◊—————————————————————————————————————————————————————————————————————◊
On the other hand, Setting up MFE Interval Reports is done via the TCE Primary, MFE
Support Interface. This MFE Specific Menu may be reached by logging onto the ICE Primary
Menu, a VTAM application or by entering the command string on the TSO/ISPF Command
Line.
TSO $CLI,*MYMFE
-NSIMCLX 0707- ICE 16.0 - MY Category Select - Multi-Factor Edit
Once in the menu “Click” under MFEdits to reveal ADMIN and AUDIT reporting functions.
If the user is a TCE ADMIN, the “Options Line” will shift to
Profile Log Permit Log MFAdmin MFE Events MFE Monitor
“Click” under MFAdmin or MFAudit to shift the “Options Line” back to its original state.
Dataset Prompts PadLock MFEdits EmlNote On-Edit DesCript
A General MFE User is an individual that has been assigned an MFE User Profile and has
been Permitted to one or more MFE Category Profiles. Such MFE users will likely experience
only the “Challenge” to enter a Token that is presented by MFE Profiled Resources when they
attempt to access. However, when the “NoEMail” is in use, the user will have to register and
maintain a “Private MFEPrefix/PIN”. To do this, they must enter the following command
sequence on the TSO/ISPF Command Line:
TSO $CLI,*MYPIN
TCE Administrators and MFE Auditors are users with elevated TCE/MFE UserIds. The
distinction between users is made in the NSEJRNxx ICE Parmlib Member using the following
Control Cards:
TCEPRIME userid
TCEADMIN (userid,userid,userid,userid,userid,userid)
The userid defined as TCEPRIME has the highest level of privilege within ICE/TCE/MFE.
MFEAUDITOR userid
MFEROAUDITOR (userid,userid,userid,userid,userid,userid)
The userid defined as MFEAUDITOR has the highest level of privilege within the Auditor
Group.
While each of these structures can be supported directly (with appropriate access rights) using
TSO/ISPF, it is not a recommended ‘Best Practice’. While, as explained below, this appears
simple, as Profiles and Permits increase in number, maintaining these manually may lead to
confusion and diminished system integrity. To avoid such difficulty, a full interactive
interface is available when using the MFE Boundary Definition Panels which may be accessed
directly from the ICE Primary Menu or from the TSO/ISPF Command Line using the
command sequence:
TSO $CLI,*MYMFE
The MFE Control Structures are explained in some detail here so that what they do and how
they do it can be more clearly understood.
4.2. NSEJRNxx
NSEJRNxx is used to define the TCE Control Journals, Panel Descriptors and Settings of
various TCE Options. MFE Settings and Options defined here include: ICE Resource Sharing,
Administrators, Auditors, WAEMAIL Controls and MFE Descriptor.
To ensure the consistent application of MFE Control across all systems in a Group, it is a
recommended ICE Best Practice to use a Shared ICE Parmlib Dataset containing a single
NSEJRNxx member.
4.2.6. DETCHNGNOTIFY
Upon entry into Controlled Datasets, MFE Compares the current content of the selected
member with the last copy stored. By default when a change is detected, a Pop-Up offering
Certification Options is displayed. In NON-MFE Categories, the DETCHNGNOTIFY
Control Card can be used to turn the Pop-Up off. If the Pop-Up is turned OFF, MFE will
dynamically override the setting and turn it back ON.
4.3. NSECTLxx
NSECTLxx Control Cards are constructed as “Sets” of - MVS Datasets, UNIX Files or Load
Libraries - bracketed by CATEGORY Statements to form a Category Control BLOCK.
4.3.1.1. TYPE
Specify ‘EDIT’ to signify that the CATEGORY will contain only MVS Partitioned or
Sequential Datasets. Do not mix Partitioned and Sequential Datasets in the same
CATEGORY. Specify ‘LOAD’ when defining a CATEGORY that contains only Load
Libraries.
4.3.1.2. ROOT
When defining a UNIX File CATEGORY, specify the Root Directory that will precede the
concatenation of Directory (DIRS) and/or File (FILE) specifications contained within the
CATEGORY.
4.3.1.3. CNTL
Set the CNTL parm ‘ON’ to capture actions such as Un-Cataloging a Dataset, Deletion of a
Module/Member, Renaming a Module/Member.
4.3.1.4. CHNG
Set the CHNG parm ‘ON’ to activate the Hourly Change Detection process for the
CATEGORY.
4.3.1.5. AUTHVFY
The MFE specific Control Card activates Multi-Factor Edit User Verification and therefore
presents a ‘Challenge’ to permitted users attempting access to resources defined within the
CATEGORY. All other unpermitted users are automatically denied/warned during an access
attempt. The following parms define these Verification actions.
• FAILMSG/FMSG
If set ‘ON’ a screen message is displayed when an access attempt is denied or token entry is
rejected. The Default is ‘ON’.
• TOKENDISP/TKND
If set ‘OFF’ the Token entry field is ‘NULL’ meaning the Token characters are not visible to
the user when entering the Token. The Default is ‘ON’.
• WARN
If the Keyword ‘WARN’ appears with the AUTHVFY Control Card, any user attempting
access will be WARNED that the resource is under MFE Controls and that they would
normally be denied access BUT that these controls have been currently relaxed to allow them
access. Recommended for use only during initial testing and training of how MFE functions
to enhance access control.
4.3.1.6. CERTVFY
Specifying this single Control Card, CERTVFY, will turn on Resource Certification Actions
during Hourly Change Detection and during resource access attempts. On-Access
Certification detection will result in the presentation of a panel showing multiple Certification
Actions and/or Options.
4.3.2. CATEGORY .END
Required, ends the CATEGORY Control Block Set.
4.4. NSEENSxx
NSEENSxx – Defines MFE User Token Delivery Profiles – User’s Direct Email Address,
3rdParty Email Address(es), NoEMail Option - and their ‘WHEN” Permitted
Categories/Profile Set. In addition, it defines the Email addresses of Administrators and/or
Auditors that will receive Notifications/Alerts and/or Interval Reporting of MFE events.
When the use of Email is NOT an option, the METHOD parm should be set to ‘NOEMAIL’.
This will result in the user, on Access Challenge, receiving a Suffix value that must be used
with the user’s Private PIN. Only the correct concatenation of this “Token Material” entered
into the challenging panel can permit access.
When the use of Email is acceptable, the METHOD parm should be set to ‘EMAIL’. This
will result in the User or a Designee receiving an Email/SMS containing a Time Sensitive,
One-Time Token. Only the correct entry of this Token into the challenging panel can permit
the user access.
4.4.1.2. 3RDPARTY
Use this Control Card to direct Token delivery to a Third Party Designee. When used, the TO
Email Address(es), one is acceptable, two advisable, must not be that of the user. This
notwithstanding the FROM must always be that of the user.
4.4.1.6. MFEPREFIX
The value of MFEPREFIX, which is maintained by the user, is always encoded using an MFE
specific substitution cipher and may only be updated using the MFE Line Command Interface
command sequence shown below.
TSO $CLI,*MYPIN.
4.4.3.2. FROM
4.4.3.3. SUBJECT
4.4.4. ACTION .END
4.4.5.2. FROM
4.4.5.3. SUBJECT
4.4.6. ACTION .END
4.4.7.2. FROM
4.4.7.3. SUBJECT
4.4.8. ACTION .END
4.4.9.2. FROM
4.4.9.3. SUBJECT
4.4.10. ACTION .END
4.4.11.1. TO
Permitted MFE User’s Email Address
4.4.11.2. ALIAS
Is used to MASK the User’s userid.
4.4.11.5. FROM
May be any valid Email Address
4.4.12. ACTION .END
Required, ends the PSWDEXP Control Block Set.
4.5. NSEDETxx
Settings in the NSEDETxx Member defines the Daily, Weekly and Monthly intervals that
function in conjunction matching NSEENSxx user and group email delivery settings.
Working together they ensure that Administrative and Audit Interval Reports are prepared
and delivered. This pairing notwithstanding NSEDETxx can work independently to create
reports that are stored as Members in Registry Datasets and made viewable via the MFE Panel
Interface.
4.5.2.2. CYCLE(WEEKLY(MON,TUE,WED,THR,FRI,SAT,SUN))
TIME(hh:mm)
4.5.2.3. CYCLE(MONTHLY(DOM(day_number)EOM))
TIME(hh:mm)
The MFE Primary Boundary Category Dialog may be reached via the ICE Primary Menu by
selecting Controls and then Boundary and then Datasets, LoadLibs or USSFiles. If Datasets
is selected, the following panel is displayed.
Vers(2) ICE 16.0 - Category Selection - MVS Datasets .. OverView
Only one Boundary Type – Datasets, LoadLibs, USSFiles – may be managed at a time. If you
wish to switch Types, PKF3 back to the Boundary Selection Menu.
Take note at the bottom of the panel ‘MFEdits’, cursor under it and press enter to reach the
MFE Primary Dialog shown below.
Vers(2) ICE 16.0 - Category Selection - Multi-Factor Edit
This Dialog may also be reached directly from the native TSO/ISPF Command Line by
entering:
TSO $CLI,*MYMFE
TSO $CLI,*MYMFE,USS
TSO $CLI,*MYMFE,LIB
Mulit-Factor Edit (MFE) is an extension of the control structures that surround a TCE
Category. When used, it requires that a category be defined as an MFE Profile. To do this,
select a Category with 'S' and press Enter. Categories with defined MFE Profiles are denoted
on panel with (v)/(c)/(b). Once a Profile is defined, all access to associated Datasets, Files &
Libraries is denied/warned unless users are specifically Permitted. Permitted users attempting
access receive a required One-Time PassTicket to continue. All related actions invoke TCE
Descriptor, Journaling and when '(c)' On-Edit Certification Detection. To Permit a user to a
Category/Profile enter 'P' adjacent to the category name and press Enter. Cursor under
MFEedit then press enter, shifts the panel to the ADMIN/AUDIT reporting view.
The Integrity Controls Environment (ICE) Application – TCE/MFE 26
This is a Simple, Straight Forward Process that Enhances z/OS Resource Defenses
Text underlined and shown in white are point-and-shoot hot spots. Cursor under and press
enter to drill-down to their supported feature. For example cursor under a Category Name
and press enter to see the names of its Category Resources.
• ‘---'
Indicates NO MFE Profile.
• ‘(v)’
Indicates that the Category has a functional Verification Profile.
• ‘(c)’
Indicates that the Category has a functional Certification Profile.
• ‘(b)’
Indicates that the Category has both a Verification and Certification Profile.
Cursor under MFAdmin/MFAudit and press enter to shift the Option Line back to its original
state.
5.4.1.1. FailMsg
By Default ON to show Message when TOKEN entry fails.
5.4.1.2. TokenDisp
By Default ON to show visible area for entry of TOKEN. When OFF, TOKEN entry area is
masked.
5.4.1.3. StartDate
Optional YY/MM/DD when MFE Controls become active. If not specified AUTHVFY takes
effect upon activation.
5.4.1.4. StartTime
Optional (24) HH:MM when MFE takes effect. If no date, daily.
5.4.1.5. StopDate
Optional YY/MM/DD when MFE Controls become inactive. If not specified, AUTHVFY
remain in effect indefinitely.
5.4.1.6. StopTime
Optional (24) HH:MM when MFE ceases. If no date, daily.
5.4.2.1. ‘S’
Enter to create a new Profile or update an existing Profile.
5.4.2.2. ‘R‘
Enter to remove an existing Profile. This action is followed by a display of UserId(s) permitted
to the profile, each of which may optionally be removed as well.
This Worksheet presents a summary of MFE Profiles with specific information about Profiles
Settings with direct access to UserIds permitted/not permitted to related Profiled resources.
Enter Report on the Command Line and then press enter to View/Move/Copy related Profile
Report(s).
Once a Category is Profiled users must be specifically permitted to it in order to gain resource
access. The panel shown below is the focal point to this activity and can be reached directly
from the MFE Primary Boundary Menu using the ‘P’ Category selection option or from the
Profile Panel that will precede it when the ‘S’ option is used and then ‘Permitted’ is selected.
◊————————— Function - UserId Permits to MFE Control Profile —————————◊
◊ ICE 16.0 MY - Multi-Factor Users Verify ◊
◊ ◊
◊ + Control Profile GHB.STAGED DENY MODE ◊
◊ ◊
◊ 01 GBAGS1 02 GBAGS2 03 PROBI1 04 05 ◊
◊ 06 07 08 09 10 ◊
◊ 11 12 13 14 15 ◊
◊ 16 17 18 19 20 ◊
◊ 21 22 23 24 25 ◊
◊ ◊
◊ Cursor under UserId or into a Blank Field and Press Enter ◊
◊ ◊
◊————————————————————————————————————————————————————————————————————◊
Having selected a UserId the user’s Permit Profile – Delivery Information and Permitted
Categories – is displayed. Confirm the selected UserId as shown in the left of the panel.
Update the user’s delivery information as needed. Check ‘/’ or Un-Check the Target Category
as necessary to add or remove.
5.7.1. Delivery
An MFE Token is dynamically generated and delivered when a Permitted UserId attempts to
access a Profile Resource.
5.7.2. Permit
UserId Permitted Profile Access with Token received at Address. If no '@' in Address, value
is assumed to be a valid UserId, WAEMAIL Lookup automatic.
5.7.3. Designee
One or Two possible alternate recipients of Token. When used, the UserId, a '/' and Email
Address are required to signify that a 3rd Party will receive the Token. The Permitted user
will not receive but is the only one who may use the token. Permitted user & Designee must
cooperate.
5.7.4. Permits
If Targeted Category/Profile is checked '/', the user is permitted. Uncheck to remove the
permission. If not checked, enter '/' to permit user to the Category/Profile. Only the Target
may be altered in these ways.
5.7.5. Updates
Changes in either Delivery/Permits are monitored. If detected when you Exit/PFK3, all
underlying control files & structures are automatically updated and activated.
Worksheet presents a view of overall MFE Categories and users that are permitted to them.
Cursor under a UserId and press enter to view users permitted resources.
5.8.1. Column Headings
Numb Worksheet Row Number.
Type DSNS = Dataset, UNIX = UNIX File, LOAD = Library.
Cntl Type of Control - None, Warn, Deny
Msg If 'On' Fail Message Pop-Up on Token Entry Failures.
Tkn If 'On' Token Entry Panel Shows View of Token Entry.
Userid The UserId Permitted to the MFE Category Profile.
Category MFE Category/Profile Name
yy/mm/dd Start - Year/Month/Day when Profile Became an Active Control.
hh:mm Start - Hour/Minute when Profile Became an Active Control.
yy/mm/dd Stop - Year/Month/Day when Profile Becomes an In-Active Control.
hh:mm Stop - Hour/Minute when Profile Becomes an In-Active Control.
5.8.2. Row Commands
‘S’ Shows the selected UserId Permit Profile Settings; Token Delivery specifics
and Permitted MFE Categories.
‘V’ View the Dataset, Libraies and Files that a UserId may Access as a result of
Permission to an MFE Category.
Selecting the “Certification” option shown on the Control Profile Definition Panel, shown
earlier, will display the Category Certification panel shown below. If the resources defined to
the profile are be “Certified” Check ‘/’ Certify, enter ‘S’ and press return. Such an update
returns to the prior panel, take note of the Verification/Certification indicator shown, upper
right, of the Control Profile Definition panel. It will either show ‘Certify’ to indicate the
Category resources are certified only or ‘Veri/Cert’ to indicate that they are both Verified and
Certified.
◊——————————— Function - Update MFE Category Certification ———————————◊
◊ ICE 16.0 MY MFE Profile Certification ◊
◊ ◊
◊ + Control Profile: GHB.STAGED .. Certify ◊
◊ ◊
◊ FailMsg TokenDisplay ---Start--- ---Stops--- ----This-Update---- ◊
◊ -On|Off ---On|Off--- yymmdd hhmm yymmdd hhmm yymmdd-hhmm-UserIds ◊
◊ /. .. /. .. 200719-1220-PROBI1 ◊
◊ ◊
◊ Select for Alert Notices or for User Permitted or for Quarantine ◊
◊ ◊
◊ Enter S .. then Press Return to Update MFE Profile ◊
◊ ◊
◊————————————————————————————————————————————————————————————————————◊
As is the case with the Control Profile Definition Panel all Profile definitions shown in this
panel may be updated equally using this panel.
5.9.1. Isolated
Curson under the white, underlined word Isolated to show a list of Isolated Resources in the
selected Category.
◊————————————————————————————————————————————————————————————————————◊
The Notification Dialog allows up to five ADMIN and Five AUDIT Recipients to be added
to the distribution list for MFE Email Alerts.
5.10.1.1. <ALLOW>
The edit was allowed to proceed because the user was permitted to the resource and proper
edit token was received and properly entered.
5.10.1.2. <WARNS>
WARN mode was active and the access allowed to occur even without a proper Token.
5.10.1.3. <FAILS>
Did the MFE access attempt fail due to the edit token having reach timeout?
Did the MFE fail due to the entry of an incorrect MFE supplied token?
5.10.1.4. <3PART>
Did a Designee receive notification of an in process access attempt?
All actions that impact a Category Profile and User Permissions are Logged and form the
basis of on-line and interval Reports. The on-line worksheets are shown and explained below.
The Worksheet shown below shows Groups of Categories with access to their individual
histories.
-NSIMRBX 0717- ICE 16.0 - MY MFE Category Profile Groups Row 1 to 9 of 9
---Audit Groups---
-------------------------- 9 Category Profile Groups --------------------------
Row Selection: List_the_Group_Records Displays_All_Current_Profile_Control_Info
--- To Sort select a Sub-Head, To Query enter above Sub-Head, PFK1 for Help ---
- Row ----Profile Group---- ------Last Updated------ ---Controls--- ---Start---
_ ___ ___ _________________ ___ ______ ____ ________ ____ ____ ____ ______ ____
S Num Ttl ---MFECategory--- Act yymmdd hhmm -UserId- Mode Fail Tokn yymmdd hhmm
_ 001 13 JIMS.TEST DEL 200717 1639 PROBI1 DCfy On On ------ ----
_ 002 7 PATS.OVERRIDE UPD 200717 1610 PROBI1 WVfy On On 200701 ----
_ 003 3 SYSTEM.PARMLIB UPD 200717 0539 PROBI1 DCfy On On ------ ----
_ 004 20 PATS.ONETIME UPD 200714 1356 PROBI1 WCfy On On 200804 ----
_ 005 3 GHB.STAGED UPD 200714 1208 GBAGS1 DVfy On On ------ ----
_ 006 7 GHB.PARMLIB UPD 200709 1144 PROBI1 DVfy On On 200701 ----
_ 007 2 RFAUL1.PARMLIB DEL 200609 1153 GBAGS2 DVfy On On ------ ----
_ 008 2 PATS.STATS DEL 200609 0900 PROBI1 DVfy On On ------ ----
_ 009 1 DTCC.PAGENT NEW 200609 0859 PROBI1 DVfy On On ------ ----
******************************* Bottom of data ********************************
A Profile Group is a collection of Profile Audit Records grouped by MFE Category Profile
by UserId. The number in Permit Column reflects unique UserId Permits. L will List the
Records by UserId. Record shown is Last update to the Profile. Enter REPORT on the
command line and press enter to View/Move/Copy related Profile Report(s).
The Worksheet below shows Groups of Permitted Users with access to their individual
histories.
-NSIMRBX 0717- ICE 16.0 - MY MFE Category Permitted Groups Row 1 to 14 of 26
---Audit Groups---
----------------------- 26 Category Permit UserId Groups ----------------------
Row Selection: List_the_Group_Records Display_UserId_Token_Delivery_Information
--- To Sort select a Sub-Head, To Query enter above Sub-Head, PFK1 for Help ---
- Row ----Permit Category Groups---- ------Last Updated------ ----Designate----
_ ___ ___ ________ _________________ ___ ______ ____ ________ ________ ________
S Num Ttl -UserId- ---MFECategory--- Act yymmdd hhmm -UserId- -Desg01- -Desg02-
_ 001 6 PROBI1 JIMS.TEST DEL 200717 1644 PROBI1 ------- -------
_ 002 7 GBAGS1 JIMS.TEST ADD 200610 1513 PROBI1 PHARL1 -------
_ 003 16 PROBI1 SYSTEM.PARMLIB UPD 200716 1120 PROBI1 ------- -------
_ 004 2 GBAGS2 SYSTEM.PARMLIB ADD 200709 1006 PROBI1 --Yes-- -------
_ 005 2 GBAGS1 SYSTEM.PARMLIB ADD 200709 1002 PROBI1 --Yes-- -------
_ 006 34 PROBI1 PATS.OVERRIDE UPD 200714 1247 PROBI1 ------- -------
_ 007 1 GBAGS2 PATS.OVERRIDE ADD 200709 1007 PROBI1 --Yes-- -------
_ 008 2 GBAGS1 PATS.OVERRIDE ADD 200709 1001 PROBI1 --Yes-- -------
_ 009 6 GBAGS2 GHB.STAGED UPD 200714 1234 GBAGS1 --Yes-- --Yes--
_ 010 2 GBAGS1 GHB.STAGED DEL 200714 1105 GBAGS1 --Yes-- --Yes—
A Permit Group is a collection of MFE Permit Audit Records grouped together by UserId.
The displayed record is the very last record for a unique UserId/Profile combination. Use the
List function to expand the Group & List all the records. Use Display function to show full
set of Token Delivery Info. Enter REPORT on command line and press enter to
View/Move/Copy related Profile Report(s).
The Control Journal is a repository of ICE Managed/Controlled Events including all MFE
Events. The panel shown below provides direct access to All Journal Records with options to
define Data Characterization, Query/Search Range/Scope and Presentation Format.
Panel supports query against all Controlled Categories with or without MFE protection. When
MFE Events are the target, it is best to select EventClass Characterization. If MFE events are
within the scope of the query, they are preceded by MEDIT followed by /Classes Name.
5.12.1.1. ALLOW
MFE OK, token was sent and subsequently validated.
5.12.1.2. WARNS
MFE WARN was triggered; AUTHVFY WARN was specified and the edit would have
otherwise been denied for either bad token, token entry timeout, or no MFEPERMT for
userid/category.
5.12.1.3. DENYS
MFE failed; the dataset/file was in an AUTHVFY defined category with no WARN and the
request to edit was failed for either a bad token, token entry timeout, or no MFEPERMT for
userid/category.
5.12.1.4. SETUP
MFE passticket generation failed. This would indicate that the security product setup required
to use the passticket generator most likely had not been done.
5.12.1.5. 3PART
Used to indicate a third party designation which would be same as ALLOW/WARNS except
for 3RDPARTY MFEPERMT use.
As datasets are accessed/updated, the event and the class of event are recorded in the Control
Journal along with related details - Metadata, Descriptor, Changes and/or the content of the
dataset/member. The Panel reflects the classification/profiling of number of datasets specified
in the prior panel. To view Datasets in a given profile, select the profile using an 'S' and press
enter. In the worksheet that follows the individual Datasets Groups are shown. Using Row
and Line Commands expand the groups, drill down into group detail and build/print reports.
This Panel serves multiple purposes. First, on entry it shows the status of MFE Interval
Monitor, current execution Time and Days and below that the availability of a given interval
for delivering a report.Second is to display the status of a provided email address. To do this,
cursor into the address field and press enter. Once the status is shown, the target address may
'Joined'/'Leave' the selected delivery option. Entering a UserId as address will call the ESM
to determine if it is known and if it has a corresponding WAEMAIL address. If address is
known, it is displayed. If user is not known, condition noted.
Cursor under the Email Address to View the associated User’s Current Delivery Schedule.
Cursor under the white text “View Last Admin Report Set” and press enter to present the Date
for the last Interval Report in each for Daily, Weekly and Monthly delivery. Cursor under the
presented dates, if any, and press enter to display the Interval Report. Note that AUDIT and
ADMIN Report Sets and Interval Delivery dates may differ.
Here you define Interval Settings. First, the Hour(24), Day(s) -MON, TUE, WED, THU, FRI,
SAT, SUN - Day(s) of Month (1-31) that define the Interval. Next, Check '/' one or more of
the Delivery Options - Daily, Weekly, Monthly. On Exit(PFK3) changes, if detected, are
activated. Entering a UserId as Email Address calls ESM to determine if known and has
WAEMAIL. If so, Address is displayed.
/******************************************************************************/
/* */
/* *MY/MFE - MFE Monitor - Interval Settings */
/* */
/* This Report Date:2020/07/20 - Time:08:50:21 - User:PROBI1 */
/* */
/******************************************************************************/
/******************************************************************************/
/* RPTDSN:IFO.TEST.$TCETEMP.REPORTS($TEMPDSN) */
/******************************************************************************/
/******************************************************************************/
/* */
/* *MY/MFE - Admin - Interval Monitor Report - Daily Delivery */
/* TCE Prime Admin UserId Defined as - PROBI1 */
/* Date:2020/07/20 - Time:06:49:02 - User:PROBI1 */
/* */
/******************************************************************************/
<> Journalled MFE Activities - New Events Starting 00:00 Y/M/D - 20/07/19
-> 01 AUDIT/DTCNG 002 - Change from outside of TCE to Controlled Dsn/Mbr
Typ TTLs mm/dd/year hh:mm:ss -Volume- -----------Dataset/File-----------
--- ---- ---------- -------- -------- ----------------------------------
6.1. *MyWHO
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and
press enter:
TSO $CLI,*MYWHO
The result is the display of the driving user’s standing – General User, TCEPrime,
TCEAdmin, MFEAuditor, MFEROAuditor. A sample is shown below:
◊——————————— You are TCEPRIME Admin & Senior MFE Auditor. ————————————◊
◊ ◊
◊—————————————————————————————————————————————————————————————————————◊
6.2. *MyHIS
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and
press enter:
TSO $CLI,*MYHIS
The result is the display of the driving user’s Journal History a sample is shown below:
-NSIMCTL 0715- ICE 16.0 - My UserId Event Group Worksheet Row 1 to 14 of 15
---UserId Group---
-------------------- 900 - Journal Entry Found for - PROBI1 -------------------
Row Selection: List_Journal_Entries_in_UserId_Group
--- To Sort select a Sub-Head, To Query enter above Sub-Head, PFK1 for Help ---
- Row ---------------Related Journal Events for Target UserId---------------- >
___ ___ __ _____ _____ ________ ________ _____ _____ ________________________
S Row Ver JF Class Event -UserId- yy/mm/dd hh:mm Volume --Controlled Datasets--
_ 001 492 LS USERS ALLOW PROBI1 20/07/25 16:53 --N/A- LGN.PWD.EVENTS
_ 002 184 MA OTHER CEACT PROBI1 20/07/25 16:42 B2WRKD IFO.TEST.PARMLIB
_ 003 010 DE AUDIT DEDIT PROBI1 20/07/24 14:36 C3RES1 SYS1.PARMLIB
_ 004 045 AE ATMPT PLOCK PROBI1 20/07/24 14:35 C3RES1 SYS1.PARMLIB
6.3. *MyPIN
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and
press enter:
TSO $CLI,*MYPIN
The result is the display of the driving user’s PIN Permit Prefix Maintenance Dialog as shown
below:
◊————————— Function - MFE UserId Permit Prefix Maintenance ——————————◊
◊ ICE 16.0 MY - MFE UserId Prefix Update ◊
◊ ◊
◊ Old Prefix: New Prefix: Confirm New: ◊
◊ ◊
◊ Enter 'S' .. and Press Enter to Update Prefix ◊
◊ ◊
◊————————————————————————————————————————————————————————————————————◊
6.4. *MyPMT
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and
press enter:
TSO $CLI,*MYPMT
The result is the display of the driving user’s Permitted Profile(s) and their Protected
Resources:
-NSIMCTL 0715- ICE 16.0 - MY Category Resource Access list Row 1 to 6 of 6
Category Controls
------------------- 6 TCE Category Control Records - PROBI1 -------------------
Row Selections: Show_Category_Select_Interface List_Dataset_Library_File_Events
To Sort select a Sub-Head, To Query enter above Sub-Head, PFK1 for Help
- Row ---Controlled--- TY -----------Category Includes----------- ---Setting---
_ ___ ________________ __ ________________________________ ______ ___ ___ ___ _
S Num ---Categories--- PE ----------DSN/LIB/USS----------- Volume Ctl Det IEx P
_ 001 SYSTEM.PARMLIB ED SYS1.PARMLIB C3RES1 ON OFF 000 -
_ 002 '' '' ADCD.Z23C.PARMLIB C3SYS1 ON OFF '' -
_ 003 '' '' FEU.Z23C.PARMLIB C3CFG1 ON OFF '' -
_ 004 '' '' USER.Z23C.PARMLIB C3CFG1 ON OFF '' -
_ 005 PATS.OVERRIDE '' PHARL2.PARMLIB.OVERRIDE B2WRKC ON ON 000 -
_ 006 PATS.ONETIME '' PHARL2.PARMLIB4 ------ ON ON 000 -
******************************* Bottom of data ********************************
6.5. *MyEML
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and press
enter:
TSO $CLI,*MYEML
The result is the display of the driving user’s WAEMAIL Status in a panel as shown below:
◊——————————————— Your WAEMAIL Address - [email protected] ———————————————◊
◊ ◊
◊—————————————————————————————————————————————————————————————————————◊
6.6. *MyDEL
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and press
enter:
TSO $CLI,*MYDEL
The result is the display of the driving user’s MFE Delivery Settings in a panel as shown
below:
◊——————————— Function - MFE Token Delivery Settings - HELEN1 ———————————◊
◊ ICE 16.0 MY - Token Deliver Settings - Email or /. NoEMail ◊
◊ ◊
◊ UserId HELEN1 WAAddr [email protected] _______________________ /. Xp ◊
◊ Start Date Time ____ End ______ Time ____ Day ______________ ◊
◊ Dsg-One .. WAAddr _________________________________________________ ◊
◊ Dsg-Two .. WAAddr _________________________________________________ ◊
◊ Delivery Alert Subject My MFE Token________________________________ ◊
◊ ◊
◊———————————————————————————————————————————————————————————————————————◊
6.7. *MyQRY
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and press
enter:
TSO $CLI,*MYQRY
The result is the display of the TCE AdHoc Query panel as shown below:
◊——————————————— Function - TCE ADHOC Query & Display ————————————————◊
◊ ICE 16.0 MY - TCE Journalled Events ◊
◊ ◊
◊ ---------------- Set the Data Characterization Profile ---------- ◊
◊ by Category .. or by EventClass .. ◊
◊ --------------------- Set the Journal Query Range --------------- ◊
◊ Begins with .. YY MM DD & Ends with .. YY MM DD ◊
◊ ---------------------- Check Presentation Format ----- .. NewOnly ◊
◊ .. Active-Matrix .. In-Summary .. MetaDetail .. FullDetail ◊
◊ ◊
◊—————————————————————————————————————————————————————————————————————◊
6.8. *MyISO
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and press
enter:
TSO $CLI,*MYISO
The result is the display of the Resources that were detected as non-conforming and therefore
recorded in the Control Journal as Isolated. Such Isolated Resource Entries are not available
of Restore operation and remain Isolated until they are Re-certified as Trusted:
6.9. *MyCLI
Enter the following Common String on the ICE/ISPF or TSO/ISPF Command Line and press
enter:
TSO $CLI,*MYCLI
<> For Accessing Control Editor - Active & Isolated Journal Records.
.. MyQRY .. MyISO
Mailing Address:
Phone:
(408) 520-7100
(800) 421-5035
FAX:
(888) 939-7099
Email Address:
Web Site:
https://www.newera.com
Technical Support: