background image

IBM United States Software Announcement

210-008

IBM is a registered trademark of International Business Machines Corporation

14

(ECDSA), and Hashed Message Authentication Mode (HMAC)), as well as z/OS

Communications Server support for IKEv2 and Federal Information Processing

Standard (FIPS) 140-2.

• Digital certificates are used in managing and working with private key/public key

encryption and are often required as part of security and compliance guidelines.

They can be used by applications to establish secure communication sessions or

to configure virtual private network (VPN) sessions, and to authenticate users and

objects. z/OS PKI Services is a complete digital certificate authority included in the

base of z/OS at no additional charge. Relatively few z/OS resources can be used

to generate thousands, even hundreds of thousands of digital certificates. Reduce

risk and reduce cost by generating and managing your own digital certificates

from z/OS.
For z/OS V1.12 z/OS PKI Services is planned to be enhanced with several usability

enhancements which are expected to reduce the amount of time and number

of manual tasks associated with finding certificate serial numbers, and issuing

renewal and revocation e-mails. New standards, such as Certificate Management

Protocol (CMP), mean devices can now request, revoke, suspend, and resume

certificates from z/OS PKI Services directly and automatically. Certificates

generated by z/OS PKI Services can also be customized for use with Microsoft

Exchange and smart card readers.

• Authentication, auditing, and compliance are growing concerns. Many laws

and standards have been recently refined, enacted, or created, governing the

protection and access of data. z/OS has a long history of resource access and

reporting capabilities built into the platform that can be useful for administering z/

OS security, monitoring for threats, and auditing usage and policy compliance. z/

OS V1.12 is planned to have significant updates for Tivoli Directory Server (LDAP)

in support of new password policy rules, improved logging, and new extensions for

access control lists.

Details on the security enhancements intended for z/OS V1.12:

• ICSF is planned to provide support for translation of external RSA tokens wrapped

with key encrypting keys into one of three smart card formats. A new callable

service, PKA Key Translate (CSNDPKT), is designed to translate an existing RSA

private key in CCA external format into a specified smart card (SC) format in

support of VISA, or the common ME or CRT format. To use this new function, you

will need an IBM System z9® or System z10 server with the Crypto Express2

feature with a minimum driver and microcode level. This function is also available

on z/OS V1.8 and higher with the z/OS V1.8, z/OS V1.9 or z/OS V1.10 with the

Cryptographic Support for z/OS V1R8-V1R10 and z/OS.e V1R8 Web deliverable

and PTF UA46713.

• An enhancement to Central Processor Assist to Cryptographic Function (CPACF)

on IBM System z10 servers with the CEX3C feature is designed to help facilitate

the continued privacy of cryptographic key material when used by the CPACF

for high-performance data encryption. Leveraging the unique z/Architecture®,

protected key CPACF is designed to help ensure that key material is not visible to

applications or operating systems when used for encryption operations. Protected

key CPACF is designed to provide significant throughput improvements for

large volumes of data and low latency for small blocks of data. In z/OS V1.12,

ICSF is planned to exploit the enhancements made to the CPACF in support of

separate key wrapping keys for DES/TDES and AES. This is designed to provide

the same functions available using the PCI card, but with the advantage of CPACF

performance.

• There are a number of improvements planned for PKI Services.

– In z/OS V1.12, PKI Services is planned to allow you to create and sign

certificates with ECC keys, in addition to RSA and DSA keys.

– RACF and PKI Services will be designed to support longer distinguished names

in digital certificates. This is intended to support your use of certificates with

very long distinguished names.

– Certain events, such as restoring a prior level of the security database, or

removing and reinstalling the Certificate Authority (CA) certificate, can cause

the security manager to return serial numbers to be used for new certificates

that have been used before. PKI Services will be designed to detect this and

Содержание ZOS V1.12

Страница 1: ...wide problems that can result from unresponsive critical components Avoiding data fragmentation and planned outages for data reorganizations With the new CA Control Area Reclaim capability applicatio...

Страница 2: ...ay not be fast enough and the system must have the ability to act quickly and decisively In a Parallel Sysplex the GRS and XCF components are planned to have the ability to automatically initiate acti...

Страница 3: ...ontrol capabilities DB2 Data Studio provides an integrated set of tooling to support all phases of the data management life cycle IMS is planned to provide a new integrated development environment and...

Страница 4: ...ions are planned for z OSMF V1 12 The z OSMF Configuration Assistant for z OS Communications Server is planned to Support the configuration of IKE version 2 Enforce RFC4301 compliance for IPSec filter...

Страница 5: ...ection functions introduced in recent releases and locating eligible I O related control blocks above the 16 MB line These health checks are designed to notify you when these functions are not being u...

Страница 6: ...each data set In z OS V1 12 partial release is planned to be extended to support releasing unused volumes in addition to releasing space on the last volume of a multivolume VSAM data set that contains...

Страница 7: ...be made to the processing of PROGxx parmlib members and to Link List Lookaside LLA processing These include support in PROGxx for passing a specified parameter to a dynamic exit automatically includi...

Страница 8: ...mlessly move to where they are needed for over a decade Parallel Sysplex provides a large single system image dynamic load balancing fault tolerance and automatic restart capabilities No other technol...

Страница 9: ...data sets The SNAP SNAPX services and dump processing including that for SVC SYSABEND SYSMDUMP and SYSUDUMP dumps and the AMASPZAP program are planned to support XTIOT The Program Management Binder w...

Страница 10: ...is being updated PDSE will be designed to improve its cross system sharing capabilities including member level sharing within a GRS complex but outside a Parallel Sysplex These changes are intended to...

Страница 11: ...isting applications within the same system and in close proximity to your corporate data residing on z OS New applications based on Java WebSphere Application Server Perl PHP XML C C Unicode HTML HTTP...

Страница 12: ...ded using the z OS UNIX System Services load service loadhfs z OS XML System Services will be updated to enhance XML schema validation support by allowing applications to extract schema location infor...

Страница 13: ...customized conversion tables using Unicode Services to replace these functions The WLM service for requesting LPAR related data REQLPDAT is planned to be enhanced to include character based data about...

Страница 14: ...ity enhancements intended for z OS V1 12 ICSF is planned to provide support for translation of external RSA tokens wrapped with key encrypting keys into one of three smart card formats A new callable...

Страница 15: ...request revoke suspend and resume certificates This is intended to allow you to use CMP in a centralized certificate generation model Elliptic Curve Cryptography ECC See more information below RACDCE...

Страница 16: ...r a defined number of failed attempts In addition when a password policy control has been received native or SDBM authentication will map RACF response codes to password policy response codes where po...

Страница 17: ...Re keying and re authentication of IKE SAs and child SAs Hash and URL specification of certificates and certificate bundles A new certbundle command which can create certificate bundles as specified b...

Страница 18: ...ase architecture for IPSec compliant systems including restrictions on the routing of fragmented packets Compliance enforcement may require minor changes to IP filters for IP traffic that is routed th...

Страница 19: ...so a single cluster can be used for scalability and performance as well as for availability and disaster recovery With z OS V1 12 Parallel Sysplex technology is planned to be updated with new health...

Страница 20: ...such problems by allowing less important data to be discarded while keeping the data from critical SMF records intact Additionally new function is planned for the SMF dump program IFASMFDL to provide...

Страница 21: ...ses from CF structure connectors One focus area in z OS V1 12 is the time it takes to shut down and restart the z OS system itself and major subsystems such as DB2 Substantial reductions in shutdown a...

Страница 22: ...ses are not associated with a particular batch job There can be considerable variation in the processor time consumed by an initiator for different jobs To help you better understand the resources con...

Страница 23: ...s Network management applications can use the requested output to monitor interface status and TCP IP stack activity z OS V1 12 Communications Server is planned to provide the following new requests G...

Страница 24: ...ns Server planned improvements include The ability to learn indirect prefix routes from IPv6 Router Advertisement messages The ability to associate preference values with all routes that are learned f...

Страница 25: ...key exchange than the currently available IKEv1 Also for z OS V1 12 z OS Communications Server IPSec and IKE support is planned to leverage z OS cryptographic modules that are designed to address the...

Страница 26: ...cords A Start record with State field API Data Flow Starts that indicates the first data sent or received by the application for the associated TCP or UDP socket An End record with State field API Dat...

Страница 27: ...he need for FIPS 140 2 validated cryptographic functions when using z OS Communications Server capabilities such as the IPSec protocol Plans related to Extended Address Volume EAV larger volume sizes...

Страница 28: ...nternet and DVD the supported tape delivery options for CBPDO ServerPac and SystemPac include 3590 3592 Note Product delivery on all 3480 and 3490 tape media is planned to be discontinued October 26 2...

Страница 29: ...es which are announced and available in your country can be ordered under the applicable standard agreements terms conditions and prices in effect at the time IBM reserves the right to modify or withd...

Отзывы: