Previous Topic: NEWLABLC Keyword—Label Associated with CertificateNext Topic: NOADSP Keyword—Prevent Data Set Security


NISTECC Keyword—Generate Key with NISTECC

Valid on z/OS

Use the NISTECC keyword to generate a key pair using the National Institue of Standards and Technology (NIST) algorithm instead of the RSA algorithm. This parameter cannot be used with the ICSF, DSA, or BPECC parameters.

Because the key is generated using ICSF PKCS #11 functions, the ICSF subsystem must be operational and configured for PKCS #11 operation. Minimally, ICSF must be at the HCR7770 level. The private key is placed in the CA Top Secret database. When ICSF is at the HCR7780 level or higher, specify PCICC or PKDSLBLto store the private key in ICSF instead of the CA Top Secret database by.

This keyword has the following format:

TSS GENCERT(acid) DIGICERT(8-byte name) NISTECC 

The keyword is used with: