Can you import a third party SSL certificate and use it to provide SSL to web services on different CICS regions?

book

Article ID: 53295

calendar_today

Updated On:

Products

CA Cleanup CA Datacom CA DATACOM - AD CA CIS CA Common Services for z/OS CA 90s Services CA Database Management Solutions for DB2 for z/OS CA Common Product Services Component CA Common Services CA Datacom/AD CA ecoMeter Server Component FOC CA Easytrieve Report Generator for Common Services CA Infocai Maintenance CA IPC Unicenter CA-JCLCheck Common Component CA Mainframe VM Product Manager CA Chorus Software Manager CA On Demand Portal CA Service Desk Manager - Unified Self Service CA PAM Client for Linux for zSeries CA Mainframe Connector for Linux on System z CA Graphical Management Interface CA Web Administrator for Top Secret CA CA- Xpertware CA Top Secret CA Top Secret - LDAP CA Top Secret - VSE

Issue/Introduction

Question:

Can a third party SSL certificate (Ex. Verisign...) be imported and the same certificate used to provide SSL to the Web Services on different CICS regions?

If so, does this cause any security concerns?

Answer:

Yes, a third party SSL certificate can be imported and the same certificate used to provide SSL to the Web Services on different CICS regions. The owner of the certificate must be CERTSITE to be able to share the certificate.

  1. The security concerns are:

    The ACIDs involved will need the appropriate permission/access to the IBMFAC(IRR.DIGTCERT.function), where 'function' could be LISTRING, LIST or GENCERT.

  2. If someone steals/copies that certificate, they will be able to get to those systems where they are shared.

Additional Information:

Please see the CA Top Secret Cookbook for more information on digital certificates. 

Environment

Release: TOPSEC00200-15-Top Secret-Security
Component: