z/OS Security Server RACF Security Administrator's Guide
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


RACF and z/OS PKCS #11 tokens

z/OS Security Server RACF Security Administrator's Guide
SA23-2289-00

Tokens are containers that hold digital certificates and keys. z/OS® supports both clear and secure keys in the PKCS #11 tokens that are provided and managed by ICSF. You can use RACF® in the following ways to define and manage certain certificate objects in a token (certificates, public keys, and private keys). Because tokens are managed by ICSF, not RACF, other applications can use ICSF functions to change tokens without updating the certificate information in the RACF database. Similarly, RACF changes to digital certificates already bound to a token are not reflected in the token information that is maintained by ICSF. Therefore, the following restrictions apply:
restrictions:
  • Deleting, altering, or renewing a RACF certificate that is bound to a token has no affect on the equivalent token objects that are managed by ICSF.
  • Deleting or altering a certificate object in a token has no effect on the following objects:
    • The equivalent RACF certificate.
    • The equivalent certificate objects in other tokens.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014