Q1. Support AT-TLS for certificate management?
A1: TAMz does not currently support AT-TLS. However the CCS Message Service team has not tested with AT-TLS and currently has no specific set of notes, so it has not been tested or verified internally.
Q2. Keyring for both TAMz and MS tasks?
A2: Yes...TAMz and Message Service tasks need their own keyrings. Some certificates may be in both rings, but both tasks should have their own ring.
Q3. For use in a multi-system sysplex, should we use the HA setup?
A3: If you want HA, then yes, you should use HA setup. For initial POC, doing a single-instance install of the CCS MS Hub may be the best and simplest option. From there, you can implement the HA setup with the lessons learned from the single-instance.