Dear Group, I believe most of you perhaps received this news flash on TWS for z/OS, If no, Please take a look below and to ensure the respective actions are taken prior to December 10th 2013,
If yes, am little unsure what to check and confirm that my environment is not affected by this although we don't use TDWC for z/OS, Can anyone shed some light on this please and that would be highly appreciated, Thanks ! *=========================================================== Tivoli Workload Scheduler for z/OS default certificates need to be renewed before December 10 2013 Flash (Alert) Abstract Tivoli Workload Scheduler default certificates expire on 10 February 2014. The default certificates that were released with Tivoli Workload Scheduler V8.3.0, V8.4.0, V8.5.0, V8.5.1, and V8.6.0 general availability expire on February 10 2014, but in some scenarios (TDWC /zOS Connector) you must renewed them before December 10 2013 due to the embedded WebSphere Application Server automatic renewing mechanism that generates new random certificates to use two months before the expiration date. To avoid broken connection between TDWC/zOS connector on December 10 2013 you need to follow section " Disabling eWAS automatic renewing mechanism".You need to apply that procedure on TDWC site. Abstract Tivoli Workload Scheduler for z/OS provides a secure, authenticated, and encrypted connection mechanism for communication based on the Secure Sockets Layer (SSL) protocol. Tivoli Workload Scheduler uses by "default" the SSL protocol in some of its communications. It also provides default certificates to manage the SSL protocol. If you don't follow the instructions on following Alert these communications after February 10 2014 will be broken. Tivoli Workload Scheduler for z/OS also provides default certificates to manage the SSL protocol that is based on a private and public key methodology. A sample JCL (called EQQRCERT) is provided to create a RACF keyring including those certificates. The same default certificates are provided with the TWS agent for z/OS. A sample JCL (called EELCERT) is provided to create a RACF keyring including them. Content Content/Submission The default certificates that were released with Tivoli Workload Scheduler for z/OS V8.5.1 and V8.6.0 general availability expire on 10 February 2014. If you have TDWC connected to z/OS connector you must renew the default certificates before December,10 2013; in case you want leave the expiration date to Febr 10 2014 see "section "Disabling eWAS automatic renewing mechanism".You need to apply that procedure on TDWC site. If you use the default certificates, and do not perform any actions before the expiration date, the connection between the following Tivoli Workload Scheduler for z/OS and Tivoli Workload scheduler components are affected: 1. Connection between the Dynamic Workload Console and the Tivoli Workload Scheduler z/OS connector. 2. Connection between the Job Scheduling Console and the Tivoli Workload Scheduler z/OS connector. 3. Custom integration based on Tivoli Workload Scheduler Java APIs (only if you create your own Java client to connect to the Tivoli Workload Scheduler z/OS connector). 4. (z-centric feature is used) The communication between the controller and the Tivoli Workload Scheduler agents for z/OS (z-centric agents), if the z-centric agent destination is defined using the HTTPS value. 5. (Dynamic scheduling feature is used) The communications between the Tivoli Workload Scheduler for z/OS controller and the Tivoli Workload Scheduler dynamic domain managers, if the broker workstation destination is defined using the HTTPS value. 6. (Cross dependencies feature is used) The communications between the Tivoli Workload Scheduler for z/OS controllers, if the remote engine workstation destination is defined using the HTTPS value. 7. (Cross dependencies feature is used) The communications between Tivoli Workload Scheduler for z/OS controllers and the Tivoli Workload Scheduler master domain manager, if the remote engine workstations destination is defined using the HTTPS value. 8. The communication between the Dynamic Workload Console and the Tivoli Workload Scheduler for z/OS controller if using the z/OS connector for WebSphere Application Server for System z. 9. (The TWS agent for z/OS is used) The connection between the Tivoli Workload Scheduler Master Domain Manager and the agent for z/OS. *=========================================================== ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
