docmain.css" /> Configuring DCAS and RACF - Automated Sign-On for Mainframe Administrator Guide

Configuring DCAS and RACF

The z/OS administrator must configure DCAS so it can communicate with the MSS Administrative Server. In addition, certain configuration steps are necessary in RACF.

The administrator must also create a TLS key database file that contains both the DCAS client’s certificate information and the DCAS server's certificate (public key) information. The MSS Administrative Server and DCAS must exchange public keys and place them in the other's trusted store.

The basic configuration steps include:

  1. Configure RACF services for DCAS.

  2. Configure DCAS and TLS on the z/OS mainframe.

  3. Set up key exchange between the DCAS server and TLS.

  4. Manage keys and certificates using RACF's Common key ring support.

  5. Define a PassTicket profile for each application.

  6. Configure the DCAS server.

  7. Start the DCAS server.

For detailed steps, see Appendix A: Configuring DCAS and RACF on z/OS.