Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add documentation for using an existing keyring and certificate #4181

Open
Joe-Winchester opened this issue Feb 12, 2025 · 1 comment
Open
Assignees
Labels

Comments

@Joe-Winchester
Copy link
Member

Is your request for enhancement related to a problem? Please describe.

The Zowe docs describe using an existing certificate with the steps to create a new keyring (owned by Zowe's functional user ID) and then connect that to the existing cert together with its CA chain.

After feedback from @colinpaicemq there is another option that we should describe, which is to point zowe.yaml at the existing keyring and cert, and do some ESM commands to allow Zowe's functional user ID to access the ring owned by a different ID.

Describe the solution you'd like

Make this scenario be one of the two preferred paths (so high up in the docs before we talk about pkcs12 and other formats). We could cover with the sample of making Zowe use the IZUSVR z/OSMF keyring with

Related doc pages

A good z/OSMF chapter with the RACF commands is at https://www.ibm.com/docs/en/zos/2.4.0?topic=configurations-configuring-zosmf-server-certificate-key-ring#d97269e717.
Another good chapter is https://www.ibm.com/docs/en/zos/3.1.0?topic=library-usage-notes

Additional context

@Joe-Winchester Joe-Winchester self-assigned this Feb 12, 2025
@balhar-jakub
Copy link
Member

The issue already lives here - zowe/zowe-install-packaging#3877

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants