12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Digital Certificate SupportAdding a Digital Certificate to an ACID RecordWhen adding a digital certificate, the DIGICERT <strong>and</strong> DCDSN keywords arerequired on the TSS ADD comm<strong>and</strong>. All other keywords are optional.The syntax <strong>for</strong> the ADD comm<strong>and</strong> follows:TSS ADD(acid|CERTAUTH|CERTSITE) DIGICERT(8-byte name) DCDSN(dsname)[START(sdate)][FOR(ddd)|UNTIL(date)][LABLCERT(label name)][TRUST|NOTRUST|HITRUST][ICSF][PKCSPASS(‘PKCSPASS PASSWORD’)]ACID—A user acid or you can specify:CERTAUTH—Is an acid in which your installation can maintain certificates thatwere generated by a third party certificate authority (<strong>CA</strong>). This acid ispre-defined in <strong>Top</strong> <strong>Secret</strong>. You cannot add a KEYRING to this ACID.CERTSITE—Is an acid in which your installation can maintain site-generatedcertificates. This acid is pre-defined in <strong>Top</strong> <strong>Secret</strong>. You cannot add a KEYRING tothis ACID.DIGICERT—Specifies a one- to eight-character ID that identifies the certificatewith the user acid.DCDSN—Specifies the MVS data set containing the digital certificate. The dataset must be defined as physical sequential (DSORG=PS) <strong>and</strong> variable blockeddata set (RECFM=VB). The data set name is entered as a fully qualified namewithout enclosed quotes. The data set must be cataloged <strong>and</strong> up to 26 characterlong (8.8.8.2).The certificate contained in the data set must be BER-encoded, PKCS-7BER-encoded, or Privacy Enhanced Mail (PEM)-encoded. PEM certificates mustbe transported to MVS as TEXT; the other <strong>for</strong>mats must be transported asBINARY. The length of the serial number <strong>and</strong> certificate authority distinguishedname must be less than 246.An example <strong>for</strong> the DCDSN comm<strong>and</strong> follows:TSS ADD(USER01) DIGICERT(DIGI0001) DCDSN(USER01.CERTIF.001)START—Specifies an optional activation date. This date is not the same as theactivation date defined in the certificate itself. The web server validates that date.This date gives the security administrator the ability to specify when thecertificate will become active on MVS.An example <strong>for</strong> the START comm<strong>and</strong> follows:TSS ADD(USER01) DIGICERT(DIGI0001) DCDSN(USER01.CERTIF.001) START(10/01/03)1–54 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!