search cancel

z/OSMF keystore type parameter for Top Secret

book

Article ID: 188941

calendar_today

Updated On:

Products

Top Secret Top Secret - LDAP WEB ADMINISTRATOR FOR TOP SECRET

Issue/Introduction

When Installing z/OSMF which keystore.type is supported by TSS:

Example:

izu.ssl.key.store.password={xor}Lz4sLCgwLTs=          

izu.ssl.key.store.saf.keyring=IZUKeyring.IZUDFLT      

izu.ssl.key.store.owner.userid=                       

izu.ssl.key.store.type=JCEHYBRIDRACFKS           <<<<=====     

izu.ssl.client.auth.supported=true                    

       

 

Environment

Release : 16.0

Component : CA Top Secret for z/OS

Resolution

The keystore type supported by each application varies from application to application.

The keystore type required by Top Secret is the keystore type that uses SAF calls to read certificates and keyrings from the external security manager like Top Secret, ACF2 and RACF.

Please consult your products documentation to determine the keystore type required to use SAF calls.

For z/OSMF  'JCERACFKS' is the keystore type that uses SAF calls to retrieve certificates from the external security manager like Top Secret, ACF2 and RACF.