Securing Connector RRSF Support

The RRSF feature of Connector for RACF ships password changes between non-managed and Connector managed RACF systems. To secure this information, this feature fully addresses the sensitivity built-in flows of password changes.

The Connector RRSF feature uses RRSF infrastructure and RRSF command-direction to ship password change events among its components. By doing so, the Connector for RACF solution relies on:

  • APPC/MVS security as deployed by the site between RRSF nodes

  • RRSF built-in confidentiality, which is achieved by using masking inter-RRSF traffic using CDMF (Commercial Data Masking facility) algorithm and secret key provided by RACF. CDMF is a form of 40-bits DEA encryption, exportable outside the United States

  • RACF confidentiality, such as non-displaying password values