Setup ACF2 Or Top Secret LDS To Use AT-TLS
search cancel

Setup ACF2 Or Top Secret LDS To Use AT-TLS

book

Article ID: 14141

calendar_today

Updated On:

Products

ACF2 ACF2 - DB2 Option ACF2 for zVM ACF2 - z/OS ACF2 - MISC PanApt PanAudit Top Secret Top Secret - LDAP

Issue/Introduction

How do you setup ACF2 or Top Secret LDS (LDAP Directory Services) to use AT-TLS?

Environment

Release:
Component: ACF2MS, TSSMVS

Resolution

You can set AT-TLS policy to create a SSL pipe for the IP/Port that your remote LDAP is running on and then configure LDS to establish a plain ldap:// connection to the SSL port of the LDAP Server. When LDS goes to connect to LDAP, AT-TLS should establish the SSL connection (like a VPN tunnel) and then allow LDS to use ldap:// over the SSL channel. The setup is all in AT-TLS and LDS just runs over that tunnel. 

The handshake role for the LDS LDAP connection should be set as a client. Review the IBM Handshake Role doc for more information.  

To avoid non-LDS LDAP client traffic matching the AT-TLS policy, you’ll probably want to specify the local IP address that LDS is using in the policy.