Dear Group,

I believe most of you perhaps received this news flash on TWS for z/OS, If
no, Please take a look below and to ensure the respective actions are taken
prior to December 10th 2013,

If yes, am little unsure what to check and confirm that my environment is
not affected by this although we don't use TDWC for z/OS, Can anyone shed
some light on this please and that would be highly appreciated, Thanks !

*===========================================================
Tivoli Workload Scheduler for z/OS default certificates need to be renewed
before December 10 2013

Flash (Alert)

Abstract
Tivoli Workload Scheduler default certificates expire on 10 February 2014.

The default certificates that were released with Tivoli Workload Scheduler
V8.3.0, V8.4.0, V8.5.0, V8.5.1, and V8.6.0 general availability expire on
February 10 2014, but in some scenarios (TDWC /zOS Connector) you must
renewed them before December 10 2013 due to the embedded WebSphere
Application Server automatic renewing mechanism that generates new random
certificates to use two months before the expiration date.

To avoid broken connection between TDWC/zOS connector on December 10 2013
you need to follow section " Disabling eWAS automatic renewing
mechanism".You need to apply that procedure on TDWC site.

Abstract

Tivoli Workload Scheduler for z/OS provides a secure, authenticated, and
encrypted
connection mechanism for communication based on the Secure Sockets Layer
(SSL)
protocol.

Tivoli Workload Scheduler uses by "default" the SSL protocol in some of its
communications.

It also provides default certificates to manage the SSL protocol. If you
don't follow the instructions on following Alert these communications after
February 10 2014 will be broken.

Tivoli Workload Scheduler for z/OS also provides default certificates to
manage the SSL
protocol that is based on a private and public key methodology. A sample
JCL
(called EQQRCERT) is provided to create a RACF keyring including those
certificates.

The same default certificates are provided with the TWS agent for z/OS. A
sample JCL
(called EELCERT) is provided to create a RACF keyring including them.
Content
Content/Submission

The default certificates that were released with Tivoli Workload Scheduler
for z/OS
V8.5.1 and V8.6.0 general availability expire on 10 February 2014.

If you have TDWC connected to z/OS connector you must renew the default
certificates before December,10 2013; in case you want leave the expiration
date to Febr 10 2014 see "section "Disabling eWAS automatic renewing
mechanism".You need to apply that procedure on TDWC site.



If you use the default certificates, and do not perform any actions before
the
expiration date, the connection between the following Tivoli Workload
Scheduler for z/OS and
Tivoli Workload scheduler components are affected:
1. Connection between the Dynamic Workload Console and the Tivoli
Workload Scheduler z/OS connector.
2. Connection between the Job Scheduling Console and the Tivoli Workload
Scheduler z/OS connector.
3. Custom integration based on Tivoli Workload Scheduler Java APIs (only
if you create your own Java client to connect to the Tivoli Workload
Scheduler
z/OS connector).
4. (z-centric feature is used) The communication between the controller and
the
Tivoli Workload Scheduler agents for z/OS (z-centric agents), if the
z-centric
agent destination is defined using the HTTPS value.
5. (Dynamic scheduling feature is used) The communications between the
Tivoli
Workload Scheduler for z/OS controller and the Tivoli Workload Scheduler
dynamic domain managers, if the broker workstation destination is defined
using the HTTPS value.
6. (Cross dependencies feature is used) The communications between the
Tivoli
Workload Scheduler for z/OS controllers, if the remote engine workstation
destination is defined using the HTTPS value.
7. (Cross dependencies feature is used) The communications between Tivoli
Workload Scheduler for z/OS controllers and the Tivoli Workload Scheduler
master domain manager, if the remote engine workstations destination is
defined
using the HTTPS value.
8. The communication between the Dynamic Workload Console and the Tivoli
Workload
Scheduler for z/OS controller if using the z/OS connector for WebSphere
Application Server for System z.
9. (The TWS agent for z/OS is used) The connection between the Tivoli
Workload Scheduler
Master Domain Manager and the agent for z/OS.


*===========================================================

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to