background image

IBM United States Software Announcement

210-008

IBM is a registered trademark of International Business Machines Corporation

17

• IBM Tivoli Directory Server for z/OS is planned to provide support for the

syntaxes and matching rules currently supported by IBM Tivoli Directory Server.

This support will be designed to allow migration and replication of schema

and directory entries using these syntaxes and matching rules from IBM Tivoli

Directory Server on other platforms.

• TSO/E will be designed to accept passwords that include one or more special

characters. This is intended to leave the checking for acceptable password

characters to an external security manager such as RACF.

• z/OS Communications Server is planned to introduce trusted TCP connections,

to enable sockets programs to retrieve sysplex-specific connection routing

information and partner security credentials for connected sockets. Partner

security credentials can be retrieved if both endpoints of a TCP connection reside

in the same z/OS image, z/OS sysplex, or z/OS subplex, and the endpoints are

within the same security domain. In such a topology, partner programs can use

trusted connections to authenticate each other as an alternative to using an SSL/

TLS connection with digital certificates for client and server authentication.

• Internet Key Exchange version 2 (IKEv2) is the latest version of the Internet Key

Exchange (IKE) protocol specified by RFC 4306. IKE is used by peer nodes to

perform mutual authentication and to establish and maintain security associations

(SAs). In z/OS V1.12 the Communications Server IKE daemon (IKED) is planned

to be enhanced to support IKEv2, in addition to its existing IKEv1 support. The z/

OS Communications Server support for IKEv2 is planned to include:
– IPv4 and IPv6 support
– A new identity type called KeyId
– Authentication using pre-shared keys or digital certificates; certificates may use

RSA or elliptic curve (ECDSA) keys

– Re-keying and re-authentication of IKE SAs and child SAs
– Hash and URL specification of certificates and certificate bundles
– A new certbundle command which can create certificate bundles as specified by

RFC 4306

• z/OS Communications Server is planned to introduce these enhancements to the

network security services daemon (NSSD) IPSec Certificate Services:
– IKEv2 support: X.509 certificate-based signature creation and validation for

IKEv2

– Elliptic Curve Digital Signature Algorithm (ECDSA) support: X.509 certificates

that contain ECDSA keys may be utilized for IKEv2 digital signature creation and

verification

– X.509 certificate trust chain support: The entire X.509 trust chain will be

taken into consideration during IKEv1 or IKEv2 digital signature creation and

verification

– Certificate Revocation List (CRL) support: CRLs may be retrieved via HTTP and

consulted during IKEv1 or IKEv2 digital signature verification

– Hash and URL support: Certificates and certificate bundles specified using the

Hash and URL format specified in RFC 4306 may be utilized during IKEv2 digital

signature creation and verification

The z/OS Internet Key Exchange daemon (IKED) is planned to be enhanced to use

these new NSSD functions when a stack is configured as a network security client.

• z/OS Communications Server is planned to introduce these enhancements to

IPSec and IKE support for cryptographic currency:
– Support for the Advanced Encryption Standard (AES) algorithm in Cipher Block

Chaining (CBC) using 256-bit keys, an addition to the previously existing 128-

bit key support. You can use the longer key length for more-sensitive data.

– Support for the Advanced Encryption Standard (AES) algorithm in Galois

Counter Mode (GCM) and in Galois Message Authentication Code (GMAC)

mode. AES in GCM is intended to provide both confidentiality and data origin

authentication. AES-GCM is a very efficient algorithm for high-speed packet

networks. AES in GMAC mode is intended to provide data origin authentication

but does not provide confidentiality. AES-GMAC, like AES-GCM, is also a very

efficient algorithm for high-speed packet networks. z/OS V1.12 Communications

Содержание ZOS V1.12

Страница 1: ...wide problems that can result from unresponsive critical components Avoiding data fragmentation and planned outages for data reorganizations With the new CA Control Area Reclaim capability applicatio...

Страница 2: ...ay not be fast enough and the system must have the ability to act quickly and decisively In a Parallel Sysplex the GRS and XCF components are planned to have the ability to automatically initiate acti...

Страница 3: ...ontrol capabilities DB2 Data Studio provides an integrated set of tooling to support all phases of the data management life cycle IMS is planned to provide a new integrated development environment and...

Страница 4: ...ions are planned for z OSMF V1 12 The z OSMF Configuration Assistant for z OS Communications Server is planned to Support the configuration of IKE version 2 Enforce RFC4301 compliance for IPSec filter...

Страница 5: ...ection functions introduced in recent releases and locating eligible I O related control blocks above the 16 MB line These health checks are designed to notify you when these functions are not being u...

Страница 6: ...each data set In z OS V1 12 partial release is planned to be extended to support releasing unused volumes in addition to releasing space on the last volume of a multivolume VSAM data set that contains...

Страница 7: ...be made to the processing of PROGxx parmlib members and to Link List Lookaside LLA processing These include support in PROGxx for passing a specified parameter to a dynamic exit automatically includi...

Страница 8: ...mlessly move to where they are needed for over a decade Parallel Sysplex provides a large single system image dynamic load balancing fault tolerance and automatic restart capabilities No other technol...

Страница 9: ...data sets The SNAP SNAPX services and dump processing including that for SVC SYSABEND SYSMDUMP and SYSUDUMP dumps and the AMASPZAP program are planned to support XTIOT The Program Management Binder w...

Страница 10: ...is being updated PDSE will be designed to improve its cross system sharing capabilities including member level sharing within a GRS complex but outside a Parallel Sysplex These changes are intended to...

Страница 11: ...isting applications within the same system and in close proximity to your corporate data residing on z OS New applications based on Java WebSphere Application Server Perl PHP XML C C Unicode HTML HTTP...

Страница 12: ...ded using the z OS UNIX System Services load service loadhfs z OS XML System Services will be updated to enhance XML schema validation support by allowing applications to extract schema location infor...

Страница 13: ...customized conversion tables using Unicode Services to replace these functions The WLM service for requesting LPAR related data REQLPDAT is planned to be enhanced to include character based data about...

Страница 14: ...ity enhancements intended for z OS V1 12 ICSF is planned to provide support for translation of external RSA tokens wrapped with key encrypting keys into one of three smart card formats A new callable...

Страница 15: ...request revoke suspend and resume certificates This is intended to allow you to use CMP in a centralized certificate generation model Elliptic Curve Cryptography ECC See more information below RACDCE...

Страница 16: ...r a defined number of failed attempts In addition when a password policy control has been received native or SDBM authentication will map RACF response codes to password policy response codes where po...

Страница 17: ...Re keying and re authentication of IKE SAs and child SAs Hash and URL specification of certificates and certificate bundles A new certbundle command which can create certificate bundles as specified b...

Страница 18: ...ase architecture for IPSec compliant systems including restrictions on the routing of fragmented packets Compliance enforcement may require minor changes to IP filters for IP traffic that is routed th...

Страница 19: ...so a single cluster can be used for scalability and performance as well as for availability and disaster recovery With z OS V1 12 Parallel Sysplex technology is planned to be updated with new health...

Страница 20: ...such problems by allowing less important data to be discarded while keeping the data from critical SMF records intact Additionally new function is planned for the SMF dump program IFASMFDL to provide...

Страница 21: ...ses from CF structure connectors One focus area in z OS V1 12 is the time it takes to shut down and restart the z OS system itself and major subsystems such as DB2 Substantial reductions in shutdown a...

Страница 22: ...ses are not associated with a particular batch job There can be considerable variation in the processor time consumed by an initiator for different jobs To help you better understand the resources con...

Страница 23: ...s Network management applications can use the requested output to monitor interface status and TCP IP stack activity z OS V1 12 Communications Server is planned to provide the following new requests G...

Страница 24: ...ns Server planned improvements include The ability to learn indirect prefix routes from IPv6 Router Advertisement messages The ability to associate preference values with all routes that are learned f...

Страница 25: ...key exchange than the currently available IKEv1 Also for z OS V1 12 z OS Communications Server IPSec and IKE support is planned to leverage z OS cryptographic modules that are designed to address the...

Страница 26: ...cords A Start record with State field API Data Flow Starts that indicates the first data sent or received by the application for the associated TCP or UDP socket An End record with State field API Dat...

Страница 27: ...he need for FIPS 140 2 validated cryptographic functions when using z OS Communications Server capabilities such as the IPSec protocol Plans related to Extended Address Volume EAV larger volume sizes...

Страница 28: ...nternet and DVD the supported tape delivery options for CBPDO ServerPac and SystemPac include 3590 3592 Note Product delivery on all 3480 and 3490 tape media is planned to be discontinued October 26 2...

Страница 29: ...es which are announced and available in your country can be ordered under the applicable standard agreements terms conditions and prices in effect at the time IBM reserves the right to modify or withd...

Отзывы: