12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Certificate Name Filtering SupportCreating Certificate Name Filter ScenariosExample 1Example 2Example 3The following <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> comm<strong>and</strong> examples are based on theprevious tree directory structure.Users who enter the system with a certificate subject that starts with:OU=NJ.OU=Sales.O=ABC Cowill be assigned acid NJDEPT1 if the certificate was issued by the VeriSigncertificate authority. If the subject matched but the certificate was issued byanother certificate authority then the user would be assigned acid NJDFLT.TSS ADD(NJDEPT1) CERTMAP(NJMAP1) LABLCMAP(‘NJ Dept 1 Map’) TRUSTIDNFILTR(‘OU=VeriSign Class 1 Individual Subscriber.O=VeriSign,Inc.L=Internet’) SDNFILTR(‘OU=NJ.OU=Sales.O=ABC Co’)TSS ADD(NJDFLT) CERTMAP(NJDFLT) LABLCMAP(‘NJ Default user’) TRUSTSDNFILTR(‘OU=NJ.OU=Sales.O=ABC Co’)Users who enter the system with a certificate subject that starts with:OU=Dept3.OU=NY.OU=Sales.O=ABC Cowill be assigned acid NYDEPT3.TSS ADD(NYDEPT3) CERTMAP(NYMAP3) LABLCMAP(‘NY Dept 3 Map’) TRUSTSDNFILTR(‘OU=Dept3.OU=NY.OU=Sales.O=ABC Co’)In this example we use additional criteria (in this case application id) to decidewhich acid to assign. Users in NY sales department Dept2 that h<strong>and</strong>le corporateaccounts (they use application BUSINESS to access the system) is assigned acidNYDEPT2B <strong>and</strong> users that h<strong>and</strong>le retail accounts (they use application RETAILto access the system) is assigned acid NYDEPT2R.The special acid name of MULTIID along with the CRITERIA parameter tells<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> that if the subject <strong>and</strong>/or the issuer name in<strong>for</strong>mationmatches, then search the CRITMAP records <strong>for</strong> a match on application namebe<strong>for</strong>e assigning an acid to the user.TSS ADD(MULTIID) CERTMAP(NYMAP2) LABLCMAP(‘NY Dept 2 Map’) TRUSTSDNFILTR(‘OU=Dept2.OU=NY.OU=Sales.O=ABC Co’) CRITERIA(CNFAPP=&CNFAPP)TSS ADD(NYDEPT2B) CRITMAP(NYCRIT2B) CNFAPP(BUSINESS)TSS ADD(NYDEPT2R) CRITMAP(NYCRIT2R) CNFAPP(RETAIL)1–78 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!