This article is the fourth in a series that describe the different z/OS TLS providers, how those providers expose their settings, which providers are used by some common IBM z/OS-based products, and some examples of changing very specific TLS settings for each provider and product.
For a complete listing of all the articles, please refer to the anchor article entitled z/OS TLS/SSL Configuration One-stop information hub
If you have a comment or question about this article or any in the series, please post it to the z/OS Communications Server discussion group on the IBM Z and Linux ONE Community. For the quickest response, please prefix your discussion subject line with “TLS Settings:”
For details on setting TLS parameters for ISV products, please consult the appropriate vendor documentation.
A quick look at the TLS protocol
Figure 1 provides a conceptual view of a “typical” TLSv1.2 handshake. For a detailed description of the exact TLS protocol flows, messages and formats, see the appropriate IETF requests for comment: