Re: Secure TN3270

2008-04-30 Thread Timothy Sipples
You'll probably also want to think about how you move users over to encrypted connections in a sensible, phased manner so that you retire the non-encrypted connections by some expeditious date certain. (How expeditious depends on the sensitivity of your applications.) And the key -- no pun

Re: Secure TN3270

2008-04-30 Thread Patrick O'Keefe
On Wed, 30 Apr 2008 17:49:57 +0900, Timothy Sipples [EMAIL PROTECTED] wrote: The following comments probably apply only to parnoid shops like mine, but I want to point out some possible stumbling blocks to implementing Timothy's suggestion. ... And the key -- no pun intended -- is to

Re: Secure TN3270

2008-04-29 Thread Betsy Jeffery
Don't expect same day service. This list is not read every minite of every day by every participant. If there is anyone roosting out there doing so - they must have a lot of time on their hands. It is not a 'chat room' as in interactive. I look at the list once in the moring as I prefer

Re: Secure TN3270

2008-04-29 Thread Scott Ford
To: IBM-MAIN@BAMA.UA.EDU Subject: Re: Secure TN3270 Don't expect same day service. This list is not read every minite of every day by every participant. If there is anyone roosting out there doing so - they must have a lot of time on their hands. It is not a 'chat room' as in interactive. I

Secure TN3270

2008-04-28 Thread Coatney, Bill
I need to set up a secure TN3270 connection on our z/OS 1.9 system. I have read through the Communications Server IP Configuration Guide and it seems like the TLS protocol would be the way to go, as opposed to the SSL protocol. Did I interpret that correctly? Also does anyone have

Secure TN3270

2008-04-28 Thread Coatney, Bill
I posted the following this morning: I need to set up a secure TN3270 connection on our z/OS 1.9 system. I have read through the Communications Server IP Configuration Guide and it seems like the TLS protocol would be the way to go, as opposed to the SSL protocol

Re: Secure TN3270

2008-04-28 Thread Lizette Koehler
You will probably get a better answer at the TCP/IP newsgroup. [EMAIL PROTECTED] Lizette I posted the following this morning: I need to set up a secure TN3270 connection on our z/OS 1.9 system. I have read through the Communications Server IP Configuration

Re: Secure TN3270

2008-04-28 Thread Coatney, Bill
: Re: Secure TN3270 You will probably get a better answer at the TCP/IP newsgroup. [EMAIL PROTECTED] Lizette I posted the following this morning: I need to set up a secure TN3270 connection on our z/OS 1.9 system. I have read through the Communications Server IP

Re: Secure TN3270

2008-04-28 Thread Rugen, Len
It probably wasn't answered because the manuals pretty much tell you how to do it. There are also examples in RedBooks. I set ours up several years ago, so I don't remember all the pain involved. What may be important is your certificate authority. If you connections are internal, then you

Re: Secure TN3270

2008-04-28 Thread Wissink, Brad [ITSYS]
@BAMA.UA.EDU Subject: Secure TN3270 I posted the following this morning: I need to set up a secure TN3270 connection on our z/OS 1.9 system. I have read through the Communications Server IP Configuration Guide and it seems like the TLS protocol would be the way to go

Re: Secure TN3270

2008-04-28 Thread Coatney, Bill
Mainframe Discussion List [mailto:[EMAIL PROTECTED] On Behalf Of Rugen, Len Sent: Monday, April 28, 2008 2:40 PM To: IBM-MAIN@BAMA.UA.EDU Subject: Re: Secure TN3270 It probably wasn't answered because the manuals pretty much tell you how to do it. There are also examples in RedBooks. I set ours up

Re: Secure TN3270

2008-04-28 Thread Coatney, Bill
- From: IBM Mainframe Discussion List [mailto:[EMAIL PROTECTED] On Behalf Of Wissink, Brad [ITSYS] Sent: Monday, April 28, 2008 2:51 PM To: IBM-MAIN@BAMA.UA.EDU Subject: Re: Secure TN3270 Bill, We did this a couple of years ago, but here are the main steps we used. If you need more detail you can

Re: Secure TN3270

2008-04-28 Thread Pat Mihalec
I setup TN2370 SSL several years ago. If you want any info you can contact me offline. Pat Mihalec Rush University Medical Center Senior System Programmer (312) 942-8386 [EMAIL PROTECTED] -- For IBM-MAIN subscribe / signoff /

Re: Secure TN3270

2008-04-28 Thread Gibney, Dave
Message- From: IBM Mainframe Discussion List [mailto:[EMAIL PROTECTED] On Behalf Of Coatney, Bill Sent: Monday, April 28, 2008 12:18 PM To: IBM-MAIN@BAMA.UA.EDU Subject: Secure TN3270 I posted the following this morning: I need to set up a secure TN3270 connection

Re: Secure Tn3270

2007-05-30 Thread Gibney, Dave
: Tuesday, May 29, 2007 2:18 PM To: IBM-MAIN@BAMA.UA.EDU Subject: Re: Secure Tn3270 Ray Prevott wrote: Just getting started on this. Any advice out there? I am on z/OS 1.7 and PCOM 5.8. Hope to use RACF to manage certificates, but I don't have a clue as to what kind I might need. Any help

Re: Secure Tn3270

2007-05-30 Thread Schramm, Rob
Additional items to consider is a SHARE presentation on SSL which was very good. And the RACF Security Administration manual does a nice job of laying out different scenerios and the needed commands. You might consider (if the client supports it) just auto-accepting the certificate. Some other

Re: Secure Tn3270

2007-05-30 Thread Alan Altmark
On Tue, 29 May 2007 14:05:25 -0500, Ray Prevott [EMAIL PROTECTED] wrote: Just getting started on this. Any advice out there? I am on z/OS 1.7 and PCOM 5.8. Hope to use RACF to manage certificates, but I don't have a clue as to what kind I might need. Any help appreciated. While not strictly

Secure Tn3270

2007-05-29 Thread Ray Prevott
Just getting started on this. Any advice out there? I am on z/OS 1.7 and PCOM 5.8. Hope to use RACF to manage certificates, but I don't have a clue as to what kind I might need. Any help appreciated. -- For IBM-MAIN

Re: Secure Tn3270

2007-05-29 Thread R.S.
Ray Prevott wrote: Just getting started on this. Any advice out there? I am on z/OS 1.7 and PCOM 5.8. Hope to use RACF to manage certificates, but I don't have a clue as to what kind I might need. Any help appreciated. You need certificates. You can BUY them from Verisign/Thawte/whatever,