SSUAEQ_3.1 - Documentation Index
Table of Contents
Unified Key Orchestrator for IBM z/OS
What's new
Security release notes
Security release notes for v3.1.0.11
Security Release Notes for v3.1.0.10 earlier
Understanding
Overview
Introducing UKO
Components and concepts
Security and compliance
Architecture
Understanding key rotation
Key states
Understanding the UKO Agent
Understanding pervasive encryption
Understanding MSDKE support
Understanding CC CAT
Understanding CC ACSP server
Understanding managed key status
Understanding Key Import
Pervasive encryption for data volumes using zkey
Understanding KEK template
How to
Key management
Managing vaults
Creating vaults
Editing vaults
Deleting vaults
Managing key templates
Creating templates
Algorithm properties
Viewing templates
Editing templates
Archiving templates
Deleting templates
Specifying custom properties
Managing keys
Creating managed keys
Viewing key list
Searching key list
Editing managed keys
Viewing associated resources
Rotating keys
Aligning keys
Viewing key versions
Deleting managed keys
Importing PE keys
MSDKE startup and configuration
MSDKE key creation in UKO
MSDKE Encryption and Decryption workflow
Importing keys into UKO
Managing keystores
Connecting to keystores
Editing keystore connections
Disconnecting from keystores
Managing keys with APIs
Crypto Connect API operations
Rotating recovery key and KEKs
Crypto Connect ACSP server
Third party integration
Setting up for zkey
Setting up for GKLM
Integration with EKMF Workstation
Viewing data set encryption status
Getting started with workflows
Getting started with CC CAT
Querying the CAT GraphQL API with Python
CC CAT GraphQL reference
Using CC ACSP
CC ACSP Java Programmer's Guide
CC ACSP CCA and PKCS#11 Programmer's Guide
Enhancing security
APF authorization
Server security definitions
UKO server and vault access roles
Crypto Connect access roles
CC CAT access roles
Agent security definitions
Mutual TLS (mTLS) authentication
Diffie-Hellman session link encryption
Granting access to vaults
Changing your password
Auditing Events
User Registry
Kafka security setup
Installation
Planning
Program requirements
SMP/E
Network configuration
Installing the UKO Base
Required user IDs
Certificates and keyrings
Database setup
Liberty angel process
Set up the generic Liberty server
Configure Liberty for UKO
Key hierarchy setup
Populating the Data sets panel
EKMF Workstation installation
Installing the UKO Agent
Setup the UKO Agent for key management
Required user IDs
Agent installation
Agent verification
Agent operation
Setup the UKO Agent for CAT
Installing Crypto Connect
Required user IDs
Certificates and keyrings
Liberty angel process
Setup the generic Liberty server
Configure Liberty for Crypto Connect
Installing Crypto Connect ACSP
Required user IDs
CC ACSP on z/OS installation
CC ACSP initial setup and customization
CC ACSP Security
Security setup
CC ACSP certificates and key rings
Additional security topics
Advanced CC ACSP topics
Operating the CC ACSP Server
CC ACSP server monitoring
Configuration management considerations
Key Label Prefixing
Using Generic UDXCALL Facility
Client installation
Java Client Installation
CCA Client Installation
PKCS#11 Client Installation
PKCS #11 CCA and EP11 Client Installation
Client Configuration Guide
Auto-Configuration Feature
Generation of Client Key and Certificate
Client configuration reference
Using the CC ACSP CCA and PKCS#11 Clients
Enable PKCS#11 CCA clients to use RACF certificates
Advanced installation topics and references
Server Configuration Reference
Apache Log4j Configuration
CC ACSP client messages
CC ACSP server messages
Mapping ICSF Reason Codes to CCA Reason Codes
CC ACSP verb mappings
Troubleshooting Tips
Problem Reporting
Installing Crypto Connect CAT
Required user IDs
Product enablement in IFAPRDxx
Setup PostgreSQL for CC CAT
Setup Kafka for CC CAT
Setup Common Data Provider
Certificates and keyrings
Liberty angel process
Setup the generic Liberty server
Configure Liberty for CAT
Setup the UKO Agent for CAT
Installing Crypto Connect MSDKE
Requesting the Crypto Connect MSDKE distributed container component
Required user IDs
Certificates and keyrings
Liberty angel process
Setup the generic Liberty server
Configure Liberty for MSDKE
Installation and configuration of MSDKE
Installing Openshift Container Platform
Migration
Backup
Installation references
RACF reference
ICSF and ACP configuration reference
Agent configuration option reference for KMGPARM
Liberty server environment variable example
Liberty java options reference
Administration
Settings
System status
Managed key analytics
Help
Troubleshooting
Agent messages reference
Getting Help and Support
FAQ
Manuals in pdf format