z/TPF - Group home

Transport Layer Security (TLS) 1.3 Support for z/TPF

  

Transport Layer Security (TLS) 1.3 is the latest iteration of the TLS protocol.

In addition to the increased security, TLS 1.3 has major differences from the earlier versions of the protocol, including the following key items:
  • Streamlined session startup
  • Enforcement of perfect forward secrecy ciphers, such as ECDHE
  • Removed unsafe ciphers and unsafe message digests
APAR PJ47183 provides support for TLS 1.3 on the z/TPF system. The following TLS 1.3 cipher suites are supported on the z/TPF system:
  • TLS_AES_128_GCM_SHA256
  • TLS_AES_256_GCM_SHA384

You can use SSL APIs to specify TLS 1.3 and TLS 1.3 cipher suites for applications that use TLS. z/TPF middleware packages also support the TLS 1.3 specification and the supported cipher suites in their respective TLS configuration files.

For more information about APAR PJ47183, see the APEDIT.