12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Digital Certificate SupportExtracting Certificates from Key RingsAuthorized applications, such as servers HTTP, TN3270, CICS, or LDAP, invokethe R_Datalib callable service (IRRSDL00) in order to retrieve certificates <strong>and</strong>private keys from a Key ring, <strong>and</strong> manage serial numbers <strong>for</strong> certain certificates.<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> supports the R_Datalib functions using its Keyringsupport. You must authorize these accesses to IRRSDL00 functions byadministering IBM resource class (IBMFAC) facility permissions <strong>for</strong> theIRR.DIGTCERT.function. Where function could be LISTRING, LIST, orGENCERT.For example, to extract a user certificate from a key ring, the user would requireaccess to IBMFAC function LISTRING:TSS ADD(dept) IBMFAC(IRR.DIGTCERT)TSS PER(acid) IBMFAC(IRR.DIGTCERT.LISTRING) ACCESS(UPDATE)TSS PER(acid) IBMFAC(IRR.DIGTCERT.LIST) ACCESS(UPDATE)TSS PER(acid) IBMFAC(IRR.DIGTCERT.GENCERT) ACCESS(UPDATE)Note: If the certificate user ID is the same as the user ID issuing the R-Datalibcall, the required authority is ACCESS (READ). If the user Id is not the same,then the required authority is ACCESS (UPDATE) or ACCESS (CONTROL).Extracting Private KeysAn application can extract the private key from a user certificate if the followingconditions are met:■■■■■The caller’s user ID is the user ID associated with the certificateThe certificate is connection to its key ring with the PERSONAL usageoption.An application can extract the private key from a CERTAUTH or CERTSITEcertificate if the following conditions are met:The caller’s user ID has at least CONTROL access to the IBMFAC resourceIRR.DIGTCERT.GENCERT.The certificate is connection to its key ring with the PERSONAL usageoption.1–68 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!