12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Digital Certificate SupportDCDSN(output-data-set-name)—The data set will be allocated <strong>and</strong> cataloged,<strong>and</strong> will contain the ouput data set from the genreq’ed digital certificate. Thedata set name will con<strong>for</strong>m to the MVS st<strong>and</strong>ards, up to a maximum of 26characters.DIGICERT—Specifies a one- to eight-character ID that identifies the certificatewith the user acid.LABLCERT—Specifies an optional <strong>and</strong> case-sensitive label to be associated withthe certificate being added to the user. Up to 32 characters can be specified <strong>for</strong>the label name. Spaces are allowed if you use single quotes. This label is used asa h<strong>and</strong>le instead of the serial number <strong>and</strong> issuer’s distinguished name, <strong>and</strong> mustbe unique <strong>for</strong> the individual user. If a label is not specified, the label field willdefault to the value specified within the DIGICERT keyword.Changing a User's CertificateUse the REPLACE comm<strong>and</strong> to update a user certificate.If the certificate has a connection to a user key ring, the certificate is replaced <strong>and</strong>all key ring connections continue with the new certificate. This lets you update auser's certificate without the need to reconnect the certificate to key rings.On a REPLACE comm<strong>and</strong>, the digital certificate that you want to update can beidentified three different ways: by using DIGICERT or LABLCERT, or by usingboth SERIALNUM <strong>and</strong> ISSUERDN.The syntax <strong>for</strong> the REPLACE comm<strong>and</strong> to replace as user certificate requires theDCDSN parameter as shown next.TSS REPLACE(acid|CERTAUTH|CERTSITE) DCDSN(dsname){DIGICERT(name)}{LABLCERT(label name)}{SERIALNUM(serial number) ISSUERDN(issuer's dist' name)}SERIALNUM—Specifies the certificate's serial number.ISSUERDN—Specifies the certificate issuer's distinguished name.Certificate Replacement (Renewal)As part of the TSS Replace comm<strong>and</strong> processing, a certificate can be replacedwithout deleting <strong>and</strong> reinserting it. To replace an existing certificate, make surethat one of the following three(3) cases is satisfied:Case #1. The certificate being added is a duplicate of the existing certificate(i.e.,has the same serial number <strong>and</strong> issuer’s distinguished name) <strong>and</strong> the labels <strong>and</strong>record keys of both certificates are the same;1–62 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!