Enabling SSL on z/OS

There are a few basic tasks which will be described in detail then are referenced in the various configuration scenarios. This document is based on z/OS 1.4 and 1.5. The gskkyman program is documented in System SSL Programming V1R4.0 SC24-5901-03 and an online copy of the document can be found at:

http://publibfp.boulder.ibm.com/cgi-bin/bookmgr/BOOKS/gska1a21/CCONTENTS

Steps required for creating certificates

  1. Create an HFS KEYRING file.
  2. Create a self-signed certificate.
  3. Create a server certificate.
  4. Create a client certificate.

Steps required to implement SSL

  1. SSL for Telnet using a server certificate.
  2. SSL for Telnet using a client certificate.
  3. SSL for FTP using server certificate.
  4. SSL for FTP using a client certificate.
  5. Express logon (ELF).
  6. SSL for CICS using a server certificate.
  7. SSL for CICS using a client certificate.