Managing keys and certificates

When certificates are added to the key database or z/OS PKCS #11 token, these are some common operations that can be performed with the certificates:

  • Show certificate/key information
  • Mark a certificate (and private key) as the default certificate for the key database or z/OS PKCS #11 token
  • Export a certificate to a file, key database, or z/OS PKCS #11 token
  • Remove a certificate (and private key) from a key database or z/OS PKCS #11 token
  • Change a certificate label
  • Create a signed ECC certificate and key
  • Create a certificate to be used with a fixed Diffie-Hellman key exchange
  • Create a certificate renewal request