z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


Sharing a private key in a key ring

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

You can share a certificate and the certificate's private key among two or more servers (user IDs) by administering profiles in either the FACILITY or the RDATALIB class. Sharing a certificate can save you the expense of purchasing a new certificate for each server and avoids the overhead of exporting and importing certificate copies.

Sharing a private key requires a high degree of authority for each server involved. The key ring containing the shared certificate must be protected and each server must be configured to access the shared key ring and have sufficient access authority to read the private key with the R_datalib callable service.

For a detailed example of the required setup, see Scenario 7: Sharing one certificate among multiple servers.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014