12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Digital Certificate SupportReconnecting Private KeysWhen generating self-signed certificates using GENCERT, a public/private keypair is built <strong>and</strong> stored within the certificate. The private key always remainswith the certificate unless it is sent to a third-party as a certificate request. Whena GENREQ certificate request is sent to a third-party, the returned certificate willnot contain the private key. This happens because private keys are not shippedas part of a certificate request.To use a third-party certificate, the private key must be re-connected to thecertificate. This is accomplished automatically when a TSS ADD comm<strong>and</strong> isissued to re-connect the third-party certificate to the same user id that has the(model) certificate. The original, self-signed certificate private key, is connectedto the new certificate.As long as the user id is the same <strong>and</strong> the public key within the third-partycertificate matches the original certificate, the private key is connected.Listing Key Ring In<strong>for</strong>mationYou can list all the acids <strong>and</strong> their keyrings associated with them by executingthe following comm<strong>and</strong>:TSS LIST(SDT) KEYRING(ALL)You can also list the associated KeyRing <strong>and</strong> LABLRING <strong>for</strong> a specific acid byexecuting the following comm<strong>and</strong>. The comm<strong>and</strong> must contain the name of theKeyRing or LABLRING already associated with the acid.TSS LIST(USER01) KEYRING(RING0001) orTSS LIST(USER01) LABLRING(LABELRING0002)Managing Certificate Serial NumbersAn application can invoke the R_Datalib callable service to manage serialnumbers <strong>for</strong> certificates.An application can increment the “last serial number issued” <strong>for</strong> a personal(user) certificate if the following conditions are met:■■The caller’s user ID is the user ID associated with the certificateThe caller’s user ID has at least READ authority to the IBMFAC resourceIRR.DIGTCERT.GENCERT.TSS PER(acid) IBMFAC(IRR.DIGTCERT.GENCERT) ACCESS(READ)Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–69

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!