DBM Data Service Configuration with Top Secret generated certificates setup
search cancel

DBM Data Service Configuration with Top Secret generated certificates setup

book

Article ID: 266132

calendar_today

Updated On:

Products

Top Secret

Issue/Introduction

DBM Data Service Configuration Values digital cerificate setup.

Environment

Release : 16.0

Resolution

 

  1. Create the root:
    TSS GENCERT(CERTAUTH) DIGICERT(ROOTCERT) SUBJECTN(subject_distinguised_name) LABLCERT(cerificate_label_name)  NADATE(expiration_date) 

  2. Create the client cert:
    TSS GENCERT(CERTSITE) DIGICERT(CLIENT) SUBJECTN(subject_distinguised_name) LABLCERT(cerificate_label_name)  NADATE(expiration_date) SIGNWITH(CERTAUTH,ROOTCERT)

  3. Create the server cerificate:
    TSS GENCERT(CERTSITE) DIGICERT(SERVER) SUBJECTN(subject_distinguised_name) LABLCERT(cerificate_label_name)  NADATE(expiration_date) SIGNWITH(CERTAUTH,ROOTCERT)

  4. Create keyring:
    TSS ADD(PLATDEV) KEYRING(keyring_name) LABLRING(keyring_label_name)

  5. Add the certificates to the keyring:
    TSS ADD(PLATDEV) KEYRNG(xxxxxxxxxxxxx) RINGDATA(CERTSITE,CLIENT) USAGE(PERSONAL)
    TSS ADD(PLATDEV) KEYRNG(xxxxxxxxxxxxx) RINGDATA(CERTSITE,SERVER) USAGE(PERSONAL)
    TSS ADD(PLATDEV) KEYRNG(xxxxxxxxxxxxx) RINGDATA(CERTAUTH,ROOT) USAGE(CERTAUTH)

  6. Authorize user to use digital certificates:
    TSS PER(PLATDEV) IBMFAC(IRR.DIGTCERT) ACC(CONTROL)

 

GENCERT command documentation.