A high-performance foundation for building and deploying networking applications on z/OS
With increasing frequency, z/OS application owners and network security administrators are being asked to update specific settings for their Transport Layer Security (TLS, formerly known as SSL) protection. There may be various factors driving these updates, including weaknesses discovered in cryptographic algorithms or TLS protocol versions, as well as pending threats to traditional asymmetric algorithms from quantum attacks.
Given the variety of TLS providers (System SSL, AT-TLS, Java TLS) and exploiters of these various providers on z/OS, rolling out a change to TLS settings across a wide range of z/OS workloads can be challenging. For each TLS-protected application or middleware instance, you need to understand which TLS provider that application or middleware uses and where and how to update the specific setting with certain providers.
This article serves as the starting point for a series of articles that describe the different z/OS TLS providers, how those providers expose their settings, which providers are used by some common IBM z/OS-based products, and examples of changing specific TLS settings for each provider and product. The following topics are covered:
In addition, the following articles cover the details for configuring settings that address specific issues:
More articles like these may be added in the future based on need and demand.
If you have a comment or question about this article or any in the series, please post it to the z/OS Communications Server discussion group on the IBM Z and Linux ONE Community. For the quickest response, please prefix your discussion subject line with “TLS Settings:”
For details on setting TLS parameters for ISV products, please consult the appropriate vendor documentation.
The authors of this series would like to thank the following individuals for their valuable input and reviews as the articles were being written:
Next article: An overview of z/OS TLS providers.
Copy
That's a significant progress - thank You very much !
Links to configuration recommendations are very useful.
Regarding TLS providers outside AT-TLS: is there a intention to switch to AT-TLS ?Or to have the choice, if special functions as Cert-->ID-Mapping are not used ?(TDS is tested with AT-TLS, but not officially mentioned)
Thanks !
1st Intention : List of Products/functions using AT/TLS or NOT
2nd intention: recommendations for setup according to most recent governance (PCIDSS, BSI, NIST)
3rd : Alternatives or SoDs regarding 1) or 2) if not possible to satisfy with recent HW/SW releases.