Top Secret

  • 1.  MFACCESS setting - where is doc?

    Posted Aug 22, 2016 01:00 PM

    I'm looking for documentation on the MFACCESS setting in TopSecret.

     

    I need to understand how this works.



  • 2.  Re: MFACCESS setting - where is doc?

    Broadcom Employee
    Posted Aug 22, 2016 01:16 PM

    "MFACCESS" is related to TSSPC (CA Top Secret PC), which is now a

    defunct product.         



  • 3.  Re: MFACCESS setting - where is doc?

    Posted Aug 22, 2016 01:39 PM

    Well, I've got a userid getting access to LOGSTRM resources and it says DORM is the mode.

     

    STC       DORM     CIARTLGR  UPDATE               OK+B 

    LOGSTRM   TSSCIA.DASD.LOGST.S0100         

     

    STC is setup with FAIL

    TSS9550I FACILITY DISPLAY FOR STC                                  

    TSS9551I INITPGM=IEESB605 ID=S  TYPE=002                           

    TSS9552I ATTRIBUTES=IN-USE,ACTIVE,SHRPRF,NOASUBM,ABEND,SUAS,NOXDEF 

    TSS9552I ATTRIBUTES=NOLUMSG,NOSTMSG,SIGN(M),NOINST,NORNDPW,AUTHINIT

    TSS9552I ATTRIBUTES=NOPROMPT,NOAUDIT,RES,NOWARNPW,NOTSOC,LCFCMD    

    TSS9552I ATTRIBUTES=MSGLC,NOTRACE,EODINIT,IJU,DORMPW,NONPWR        

    TSS9552I ATTRIBUTES=LUUPD                                          

    TSS9553I MODE=FAIL  DOWN=GLOBAL  LOGGING=INIT,SMF,MSG              

    TSS9554I UIDACID=8 LOCKTIME=000 DEFACID=*NONE*   KEY=8             

    TSS0300I  MODIFY   FUNCTION SUCCESSFUL                 

     

    Where would it be getting the DORM setting from?           



  • 4.  Re: MFACCESS setting - where is doc?

    Posted Aug 26, 2016 02:27 PM

    The CIA log stream is updated from the Top Secret address space.  The user associated with the Top Secret address space is considered in DORMANT mode and security authorizations are typically bypassed to ensure the user will not get suspended nor will the address space be cancelled due to violation threshold processing.  What you see in the log does not indicate the STC facility is in DORM mode, it represents the user being in DORM mode, similar to what you would see if you permitted MODE(DORM) to any user.