I found the SSL undertaking in z/VM _MUCH_ quicker and easier than in z/OS.


I could make self-signed certs work in z/VM where I never could in z/OS.

On Thu, Apr 22, 2010 at 10:11 AM, Bob Heerdink <[email protected]>wrote:

> Thanks, I now see this is not a trivial undertaking... I hope someone has
> some GSKKYMAN execs...
>
>
> With z/VM Version 5 Release 4.0 (540), the SSL server is implemented as a
> CMS-based server for which the key database is maintained in the z/VM Byte
> File System (BFS), and which is managed via a stand-alone utility program,
> gskkyman.
>
> More information about this level of the SSL server is available via the
> Migration Considerations page and TCP/IP Planning and Customization.
>
> Important Notes:
>
> PTF Requirements
> The PTF for APAR PK65850 must be installed to enable the SSL server. The
> PTF for this APAR became available 12 December 2008.
>
> Also, check the Service Updates page for detailed information about service
> updates that are available and necessary for running the z/VM SSL server.
>
>
> Compatibility
> Prior-level SSL server implementations cannot be used with z/VM 540, nor
> can the 540 level of the SSL server be used with prior levels of z/VM.
>
> A z/VM level 520 or 530 level certificate database cannot not be relocated
> and used as-is by the z/VM 540 SSL server. To migrate certificates (with
> private keys) from a 530 level certificate database, to that used by the
> 540 level SSL server, the PTF for APAR PK75661 must be installed.
>
> Detailed information for installing the updated RPMs provided by this PTF,
> and instructions for migrating certfificates for use by a z/VM 540 (or
> later) SSL server can be found at the TCP/IP for z/VM 530 SSL Server:
> Certificate With Key Export Support page.
>



-- 
Mark Pace
Mainline Information Systems
1700 Summit Lake Drive
Tallahassee, FL. 32317

Reply via email to