11.07.2015 Views

z/OS Security and PKI services

z/OS Security and PKI services

z/OS Security and PKI services

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Application Transparent TLS (AT-TLS) Overview•Solution:ƒTCP/IP stack performs TLSBNo application changesrequiredBTake advantage of z/<strong>OS</strong>unique encryptionƒTLS Configuration throughsystem wide policiesƒGUI supplied to easeconfigurationƒOptional API for applicationsthat wish to be “aware” orcontrol TLS informationOptional APIs forTLS-awareapplications tocontrol start/stop ofTLS sessionEncryptedApplicationsSocketsSystem SSL callsTCPApplicationTransparentTLS policy flatfileUDPIP Networking LayerNetwork InterfacesPolicyAgent507.04.2006 IBM SystemsIP<strong>Security</strong> Overview – Dynamic Key Distribution• SAs can be negotiated dynamically using Internet Key Exchange (IKE) Protocolƒz/<strong>OS</strong> Cryptographic Services System Secure Sockets Layer (System SSL)ƒPhase 1 SAs are negotiated to protect IKE traffic (IKE tunnel)ƒPhase 2 SAs are negotiated to protect IP traffic (IPSEC tunnel)• IPSEC SAs provide authentication, integrity, <strong>and</strong> data privacy – 2 security protocols:ƒBased on <strong>Security</strong> Associations (SAs) – defines type of service between 2 endpointsƒAuthentication Header (AH) – authentication/integrityƒEncapsulating <strong>Security</strong> Payload (ESP) – data privacy with optional authentication• Transparent to upper layersServer<strong>and</strong>TrustedCA'sCertificateIKERACF1. Negotiate phase I <strong>Security</strong> Association (Get amaster key)2. Negotiate <strong>Security</strong> Associations (phase II)3. Generate session keys, refresh keys <strong>and</strong> SAsServer<strong>and</strong>TrustedCA'sCertificateIKERACFInstall SAs <strong>and</strong>filters into IP stackSockets APITCP/UDPIP/ICMPData LinkIPSec <strong>Security</strong> Association(s)Sockets APITCP/UDPIP/ICMPData Link607.04.2006 IBM Systems

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!