12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Digital Certificate SupportAn additional feature of <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> lets you check to see if a certificatehas already been added to the <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> <strong>Security</strong> File <strong>and</strong> with whatacid it is associated. Also, once a certificate has been added to <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong><strong>Secret</strong> it can be exported to a new data set.See the Comm<strong>and</strong> Functions Guide <strong>for</strong> exp<strong>and</strong>ed details beyond what ispresented in this Cookbook.The user ACID record can be administered with the TSS ADDTO, REPLACE,REMOVE, GENCERT, GENREQ, EXPORT, <strong>and</strong> CHKCERT comm<strong>and</strong>s.■■■■■■Use ADD <strong>and</strong> REPLACE to add or replace a certificate, label, or the START,FOR, UNTIL, TRUST, HITRUST <strong>and</strong> NOTRUST parameters.Use REMOVE only to remove the certificate from the user.Use GENCERT to generate a certificate from <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> <strong>and</strong> addit to a user.Use GENREQ to generate a PKCS#10 base 64-encoded digital certificaterequest <strong>and</strong> writes it to a data set.Use EXPORT to export a certificate from <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> to a new dataset.Use CHKCERT to see if a certificate has been added to the <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong><strong>Secret</strong> security file <strong>and</strong> with what acid it is associated.Associating a Unique Digital Certificate with a UserDigital certificates issued by a certificate authority are associated with a user byadding the certificate to the user's ACID record, or the predefined acidCERTAUTH or CERTSITE. If <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> generates a certificate it isadded to the user's ACID record when the certificate is created using the TSSGENCERT comm<strong>and</strong>.The certificate must be unique to the user. A certificate can be added to only oneuser's ACID record. Certificates can be shared only when they are attached to akey ring.1–52 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!