12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Digital Certificate SupportDCDSN(request-data-set-name)—Specifies the name of an optional data set thatcontains the PKCS#10 certificate request data. The request data set name can bethe output from a TSS GENREQ comm<strong>and</strong>. The request data contains the user'sgenerated public key <strong>and</strong> X.509 distinguished name. The request data must besigned, DER-encoded, <strong>and</strong> then Base64 encoded according to PKCS#10 st<strong>and</strong>ard.The data set must be cataloged <strong>and</strong> up to 26 characters long (8.8.8.2).If DCDSN is not specified, <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> does not generate a key pairbecause this data set contains the user's public key. If DCDSN is specified,SIGNWITH must also be specified because the request-data-set-name (inDCDSN) does not contain a private key.An example <strong>for</strong> the DCDSN comm<strong>and</strong> follows:TSS GENCERT(USER01) DIGICERT(DIGI0001) DCDSN(USER01.CERTIF.001)SUBJECTN—The attributes can consist of 229 characters if it is a self-signedcertificate. Otherwise, if it is a non-self signed certificate, the maximum length is225-characters. You can use A-Z <strong>and</strong> 0-9. The only exception is ST=STATE orPROVINCE. This is a 2-digit value field. If DCDSN or SUBJECTN is notspecified, the SUBJECTN will default to the acid name field. Note: If any of thevalues contain blanks, they must be enclosed in double quotes. The completeSUBJECTN phase must be enclosed in parenthesis <strong>and</strong> single quotes.An example <strong>for</strong> the SUBJECTN comm<strong>and</strong> follows:TSS GENCERT(USER01) DIGICERT(DIGI0001) SUBJECTN(‘CN=”Ted User” ST=NJ’)ALTNAME—Specifies the appropriate values <strong>for</strong> the SubjectAltname extension,of which one or more values might be coded. There is no default. The followingare possible values that can be used:■■■IP—Specifies a string containing a fully qualified IP address in IPV4 dotteddecimal <strong>for</strong>m, which is four decimal numbers (each number must be a valuefrom 0-255) separated by periods.For example: 203.9.102.100DOMAIN—Specifies a string containing a fully qualified internet domainname.For example: <strong>CA</strong>.COMEMAIL—Specifies a string containing a fully qualified email address.For example: david@kindgom.netImplementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!