12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Certificate Name Filtering SupportDCDSN—Specifies the name of a data set that contains a digital certificate. TheSDNFILTR or IDNFILTR data must match a portion of the subject/issuer’sdistinguished name extracted from the certificate. The distinguished name fromthe point of the match to the end of the name is used as the filter data.TRUST/NOTRUST—When specified it indicates whether this mapping can beused to associate a userid to a certificate presented by a user accessing thesystem. If neither TRUST nor NOTRUST is specified, the default is NOTRUST.Managing Criteria MapsWhen the acid is MULTIID <strong>and</strong> the CRITERIA keyword was specified on the TSS ADDCERTMAP comm<strong>and</strong>, criteria data must be defined in CRITMAP records to identify theacid to be associated with a certificate. The acid name on the CRITMAP record identifiesthe user when the filter that matched the certificate was <strong>for</strong> acid MULTIID. The TSSADD|REM|REPL|LIST comm<strong>and</strong>s is used to manage criteria maps. The syntax of theADD comm<strong>and</strong> follows:TSS ADD(userid) CRITMAP(recid){SYSID(system identifier)}{CNFAPP(application name)}{CNFUVAR(site variable list)}Userid—Name of the acid to be associated with this filter.CRITMAP—Unique 8-byte record identifier.SYSID—The system identifier. A maximum of 4 characters can be specified <strong>and</strong>the value can contain an asterisk (*) <strong>for</strong> masking.CNFAPP—The application variable. A maximum of 8 characters can be specified<strong>and</strong> the value can contain an asterisk (*) <strong>for</strong> masking.CNFUVAR—A list of application-defined variables that are defined asCRITERIA keyword data. This field can contain up to 255 uppercase characters.Implementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–77

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!