Another possible option is to configure an IKEv2/IPsec tunnel between z/OS
and Microsoft Windows Server, then run your message traffic over the
encrypted IPsec connection. For your colleagues, Microsoft documents some
configuration procedures here ("Devices not joined to a domain"):
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/securing-end-to-end-ipsec-connections-by-using-ikev2
I concur with the advice to upgrade z/OS 1.12 and the rest of the software
stack to supported releases that are still receiving security and
integrity updates.
- - - - - - - - - -
Timothy Sipples
I.T. Architect Executive
Digital Asset & Other Industry Solutions
IBM Z & LinuxONE
- - - - - - - - - -
E-Mail: [email protected]
----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN