The following JCL illustrates the requirements for one possible configuration. In this example, the certificate named BWCP_Server_Cert is the personal certificate that is used to secure the connection. It has been exported with its private key included as a P12 file.
The signing certificate, Cloud Software Group, Inc.CA is exported as a DER-formatted certificate without its private key because it is not needed. There is no need to expose the signing certificate outside of RACF.
This example shows a set of AT-TLS rules customized to configure ports for use with the personal certificate created in the
Example. Your z/OS network administrator is familiar with the documentation required to make the customizations needed for your system. Note that, to make the necessary customization, you must be aware of the keyring, label and personal certificate name stored in RACF.