WebSphere Portal, Express Beta Version 6.1
Operating systems: i5/OS, Linux,Windows


 

Creating users

This topic provides information on setting up users for DB2 for z/OS to work with WebSphere Portal Express.

  1. Create all database user IDs in the security product you are using on z/OS. For jcrschema, the database schema name for Content Repository data, create a group and connect it to the database user ID for Content Repository data, icmadmin. The following sample shows the RACF definition of such a user ID and group, where icmadmin is the database user ID for Content Repository data, yourDefaultUserGroup is your default RACF group for database user IDs, jcrschema is the database schema name for Content Repository data, and yourDefaultGroup is your default RACF group for groups. If you have some other security product such as Top Secret or ACF2 instead of RACF, translate the sample RACF definition into the appropriate syntax before executing.
    ADDUSER icmadmin DFLTGRP(yourDefaultUserGroup) NAME('WAS DB2 ACCESS USER')
    PW USER(icmadmin) NOINTERVAL
    ALU icmadmin PASSWORD(********) NOEXPIRED
    ADDGROUP jcrschema SUPGROUP(yourDefaultGroup)
    CONNECT icmadmin GROUP(jcrschema)
  2. Run the following SQL statements using a tool like SPUFI while logged on to the DB2 subsystem to grant appropriate rights on the newly created databases. If you are configuring multiple WebSphere Portal Express instances to use a single DB2 for z/OS subsystem, be sure to use the database user associated with the WebSphere Portal Express instance you are setting up.
    GRANT DBADM ON DATABASE releasenameonzos TO releaseusr WITH GRANT OPTION;
    GRANT USE OF ALL BUFFERPOOLS TO releaseusr;
    GRANT DBADM ON DATABASE communitynameonzos TO communityusr WITH GRANT OPTION;
    GRANT USE OF ALL BUFFERPOOLS TO communityusr;
    GRANT DBADM ON DATABASE customizationnameonzos TO customizationusr WITH GRANT OPTION;
    GRANT USE OF ALL BUFFERPOOLS TO customizationusr;
    
    GRANT DBADM ON DATABASE jcrdbnameonzos TO icmadmin WITH GRANT OPTION;
    GRANT USE OF ALL BUFFERPOOLS TO icmadmin;
    GRANT DBADM ON DATABASE fdbkdbnameonzos TO feedback WITH GRANT OPTION;
    GRANT USE OF ALL BUFFERPOOLS TO feedback;
    GRANT DBADM ON DATABASE lmdbnameonzos TO lmdbusr WITH GRANT OPTION;
    GRANT USE OF ALL BUFFERPOOLS TO lmdbusr;
    GRANT SELECT ON SYSIBM.SYSCOLUMNS TO releaseusr;
    GRANT SELECT ON SYSIBM.SYSCOLUMNS TO communityusr;
    GRANT SELECT ON SYSIBM.SYSCOLUMNS TO customizationusr;
    
    GRANT SELECT ON SYSIBM.SYSTABLES TO releaseusr;
    GRANT SELECT ON SYSIBM.SYSTABLES TO communityusr;
    GRANT SELECT ON SYSIBM.SYSTABLES TO customizationusr;
    
    GRANT SELECT ON SYSIBM.SYSCOLUMNS TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSTABLES TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSCOLUMNS TO fdbkdbusr;
    GRANT SELECT ON SYSIBM.SYSTABLES TO fdbkdbusr;
    GRANT SELECT ON SYSIBM.SYSCOLUMNS TO lmdbusr;
    GRANT SELECT ON SYSIBM.SYSTABLES TO lmdbusr;
    GRANT SELECT ON SYSIBM.SYSFOREIGNKEYS TO releaseusr;
    GRANT SELECT ON SYSIBM.SYSFOREIGNKEYS TO communityusr;
    GRANT SELECT ON SYSIBM.SYSFOREIGNKEYS TO customizationusr;
    
    GRANT SELECT ON SYSIBM.SYSFOREIGNKEYS TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSFOREIGNKEYS TO fdbkdbusr;
    GRANT SELECT ON SYSIBM.SYSFOREIGNKEYS TO lmdbusr;
    GRANT SELECT ON SYSIBM.SYSRELS TO releaseusr;
    GRANT SELECT ON SYSIBM.SYSRELS TO communityusr;
    GRANT SELECT ON SYSIBM.SYSRELS TO customizationusr;
    
    GRANT SELECT ON SYSIBM.SYSRELS TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSRELS TO fdbkdbusr;
    GRANT SELECT ON SYSIBM.SYSRELS TO lmdbusr;
    GRANT USE OF STOGROUP jcrstogroup TO icmadmin;
    
    GRANT SELECT ON SYSIBM.SYSTABLESPACE TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSVIEWS TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSDUMMY1 TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSTRIGGERS TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSINDEXPART TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSINDEXES TO icmadmin;
    GRANT SELECT ON SYSIBM.SYSSYNONYMS TO icmadmin;
    where:

  3. Grant the necessary access rights to all users who might require them. Depending on the architecture that you choose, these users might include a Member Manager and Java Content Repository and Feedback users.
Parent topic: Configuring DB2 for z/OS
Library | Support | Terms of use |