12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Certificate Name Filtering SupportTSS LIST(MARY001) DATA(ALL,PASSWORD)TSS ADD(MARY001) KEYRING(ACCOUNTG) LABLRING(‘ACCOUNTING-DEBT’) -RINGDATA(PAUL001, PAULCT02) DEFAULT USAGE(PERSONAL)TSS ADD(MARY001) KEYRING(ACCOUNTG) LABLRING(‘ACCOUNTING-DEBT’) –RINGDATA(JAMES01, JIM02) USAGE(CERTSITE)TSS ADD(MARY001) KEYRING(PERSONEL) LABLRING(‘PERSONEL-NEW HIRES’) –RINGDATA(TEDD01, TEDCERT1) USAGE(CERTAUTH)TSS LIST(MARY001) KEYRING(ACCOUNTG)TSS LIST(MARY001) SEGMENT(ALL)TSS LIST(MARY001) DATA(ALL)TSS LIST(MARY001) SEGMENT(CERTDATA)TSS LIST(MARY001) SEGMENT(RINGDATA)TSS LIST(SDT) KEYRING(ALL)TSS LIST(SDT) DIGICERT(ALL)TSS LIST(SDT) LABLRING(‘ACCOUNTING-DEBT’)Certificate Name Filtering SupportPrior to this support level, digital certificates had to be individually defined to<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> to be associated with an acid. Certificate name filtering(CNF) support allows certificates to be associated with users without having toadd each certificate to the <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> security file. This decreases theamount of storage <strong>and</strong> the administration needed to support a large number ofcertificates.Certificate name filtering allows profiles based on the certificate subject/issuerdistinguished name to be used to select the acid to assign <strong>for</strong> a particularcertificate. Many certificates can be associated with a single acid. This supportprovides more granular access control <strong>and</strong> accountability.When a certificate name filter is defined, the in<strong>for</strong>mation is stored in aCERTMAP record in the SDT on the security file. The filter definition specifiesthe significant portion of the issuer's or subject’s distinguished name that is usedto associate an acid with a certificate. Also, additional criteria can be specified toidentify the acid to be used. <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> supports two system variables(system id <strong>and</strong> application id) that can be used to select the acid. Sites can alsodefine their own variables to be used as selection criteria. Criteria data is storedin a CRITMAP record in the SDT. CERTMAP <strong>and</strong> CRITMAP records are createdwith the TSS ADD comm<strong>and</strong>.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!