Previous Topic: Configuring Output DescriptorsNext Topic: Export Certificates from the gskkyman Database


Set Up a Secure FTP Connection for Deployment

You can set up CA CSM to support the ability to deploy products to remote systems using FTP over TLS (Transport Layer Security). This feature allows for data to be exchanged in a secure, encrypted manner.

This feature uses X.509 digital certificates.

Certificates can be read from a security manager (CA Top Secret for z/OS, CA ACF2 for z/OS, or IBM RACF) using SAF key rings, or from USS Java key stores. In addition, CA CSM provides support for sites that use the IBM Integrated Cryptographic Service Facility (ICSF) for hardware certificate management.

The following table summarizes the available key store types that CA CSM supports:

Storage

Certificate Management

Key Stores

Security Manager

Software

JCERACFKS

Security Manager

Hardware

JCECCARACFKS

USS

Software

JKS, JCEKS, PKCS12

USS

Hardware

JCECCAKS

Note: For more information about key store types available under Java, see the Security Reference for IBM SDK, Java Technology Edition.

Follow these steps:

  1. Click the Settings tab, and click the Software Deployment link under System Settings in the Settings section on the left side.

    The Deployed Software page opens.

  2. In the Key Store Settings section, select the type of the key store that you want to use.

    The fields in the section appear. The fields vary depending on the selected key store type.

  3. Set up values for the fields, and click Apply.

    A dialog that shows the progress of the task opens. When the task completes, you can click Show Results on the Progress tab to close this dialog. The task output browser opens and you can view the action details. Click Close to close the task output browser.

    Note: While a task is in progress, you can perform other work. You can click Hide to exit the dialog and view the task status later on the Tasks tab.

    The FTP connection settings are saved.

  4. Add an FTP location. When adding an FTP location, select the check box Enable Secure FTP Transmission.

    The FTP location with secured FTP transmission enabled is added.

    You can now deploy products using FTP over TLS.

Note: For more information about adding an FTP location, see the online help.

More information:

Export Certificates from the gskkyman Database