01.01.2013 Views

CICS Transaction Gateway V5 The WebSphere ... - IBM Redbooks

CICS Transaction Gateway V5 The WebSphere ... - IBM Redbooks

CICS Transaction Gateway V5 The WebSphere ... - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8.2.1 Configuring the server certificate<br />

We configured a server key database for use with System SSL and a server<br />

keystore file for use with JSSE. System SSL used a test certificate from a<br />

certificate authority, whereas JSSE used a self-signed certificate.<br />

System SSL<br />

For System SSL it was necessary to create a server key database, request an<br />

externally signed test certificate, and receive this certificate into our key<br />

database.<br />

Creating a key database on z/OS<br />

We performed the following steps to create our key database on z/OS:<br />

1. In a z/OS UNIX System Services shell we changed directory to the HFS<br />

directory /web/scsctg5 that we were using for our <strong>CICS</strong> TG for z/OS<br />

installation, and entered the gskkyman command to invoke the <strong>IBM</strong> Key<br />

Management Utility.<br />

2. From this menu, we selected Option 1 (Create new key database), as<br />

shown in Example 8-1.<br />

Example 8-1 Creating a new key database<br />

<strong>IBM</strong> Key Management Utility<br />

Choose one of the following options to proceed.<br />

1 - Create new key database<br />

2 - Open key database<br />

3 - Change database password<br />

0 - Exit program<br />

Enter your option number: 1<br />

3. We continued by replying to the following prompts, as shown in Example 8-2.<br />

Example 8-2 Entering details of the new key database<br />

Enter key database name or press ENTER for "key.kdb": systemssl.kdb<br />

Enter password for the key database.......><br />

Enter password again for verification.....><br />

Should the password expire? (1 = yes, 0 = no) [1]: 0<br />

<strong>The</strong> database has been successfully created, do you want to continue to work<br />

with the database now? (1=yes, 0=no) [1]<br />

Chapter 8. SSL connections to the <strong>Gateway</strong> daemon on z/OS 191

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!