Setting up AT-TLS for Tivoli Management Services on z/OS components

To protect your data, you should encrypt all communication channels that are used by Tivoli Management Services on z/OS components. You can use Application Transparent Transport Layer Security (AT-TLS) to achieve secure communication.

Setting up AT-TLS for use with Tivoli Management Services on z/OS components is required if you plan to use HTTPS for communication between the Tivoli Enterprise Monitoring Server (TEMS) and other components, such as the SOAP server, the IBM Tivoli Monitoring Service Console, the tacmd CLI, and TEMS REST services.
Important: The tasks in this section require the following prerequisites:
To update your existing AT-TLS configuration to enable secure connections for Tivoli Management Services on z/OS components, complete the following steps:
  1. Create digital certificates and key ring using RACF.
  2. Define AT-TLS policy rules.
Note: The examples that are provided are intended as a guide; you can organize your certificates and AT-TLS rules differently, depending on the requirements of your site.