Disabling AES 256 Encryption
search cancel

Disabling AES 256 Encryption

book

Article ID: 12873

calendar_today

Updated On:

Products

Top Secret Top Secret - LDAP

Issue/Introduction



Need to apply RO86945 but we are not ready to convert to AES 256 encryption. Is there a way not to use AES 256 encryption in CA Top Secret?

Environment

Release: TOPSEC00200-15-Top Secret-Security
Component:

Resolution

The CA Top Secret Control Option that determines what kind of password encryption is used is the 'ENCRYPT' control option which is documented at:

https://docops.ca.com/ca-top-secret-for-z-os/16-0/en/using/issuing-commands-to-communicate-administrative-requirements/keywords/encrypt-keywordenable-or-disable-levels-of-encryption

Switching to a different encryption requires the security file to be converted with TSSXTEND.