Client considerations

When a user selects certificate in connection properties and then connects to the host, the client will request a list of available certificates from the user's workstation and prompt the user to select a certificate for authentication. The certificate doesn't need to be imported into the Eclipse-based client or stored in the client's keystore. By default, the client filters the list to only show certificates with an hostIdMappings extension, which determines the user ID used for authentication. If your certificate does not have a hostIdMappings extension and your site relies on z/OS mapping a certificate to the user ID, then you must clear the hostIdMappings object identifier (OID) filter to show all certificates from the menu (Window > Preferences > Client Certificates). If no certificate is available, the client will display Set up your Certificate message and prompt the user to set up a new one.