12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Digital Certificate SupportCase #2. The certificate being added is NOT a duplicate of the existing certificate,has the same subject’s distinguished name, issuer’s distinguished name, <strong>and</strong>public key as the existing certificate, the end date <strong>and</strong> time on the certificatebeing added is later than on that of the existing certificate, the existing certificateis NOT expired, <strong>and</strong> the record keys of both certificates are the same;Case #3. The certificate being added is NOT a duplicate of the existing certificate,has the same public key as the existing certificate, there is a private keyassociated with the existing certificate in the database, the existing certificate isNOT expired, <strong>and</strong> the record keys of both certificates are the same.An example <strong>for</strong> the REPLACE comm<strong>and</strong> follows:TSS REPLACE(USER01) DIGICERT(DIGI0001) DCDSN(USER1.CERT.DATA)Changing a Certificate's StatusThe trust status of a certificate can be changed <strong>for</strong> a specified user or certificateauthority. The status of the certificate is updated according to whether TRUST,NOTRUST or HITRUST is specified on the comm<strong>and</strong>.Important! HITRUST is only valid <strong>for</strong> the Acid named CERTAUTH.On a REPLACE comm<strong>and</strong>, the digital certificate that you want to update can beidentified three different ways: by using DIGICERT or LABLCERT, or by usingboth SERIALNUM <strong>and</strong> ISSUERDN.The syntax <strong>for</strong> the REPLACE comm<strong>and</strong> follows:TSS REP(acid|CERTAUTH|CERTSITE) {DIGICERT(name)}{LABLCERT(label name)}{SERIALNUM(serial number) ISSUERDN(issuer's dist' name)}TRUST|NOTRUST|HITRUSTAn example <strong>for</strong> the REPLACE comm<strong>and</strong> follows:TSS REPLACE(user1) DIGICERT(cert0001) NOTRUSTChanging a Certificate's LabelThe label <strong>for</strong> a certificate can be changed. The syntax requires that the certificate<strong>for</strong> which the label is being updated be identified using DIGICERT or by usingSERIALNUM <strong>and</strong> ISSUERDN.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–63

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!