Install Advanced Message Security on z/OS
We can install Advanced Message Security on z/OSĀ® by using SMP/E.
About this task
Advanced Message Security for z/OS (AMS) extends IBM MQ to provide a high level of protection for sensitive data flowing through the IBM MQ network using a public key cryptography model.
For information about licensing for Advanced Message Security for z/OS, see IBM MQ license information and IBM MQ for z/OS product identifiers.
Advanced Message Security for z/OS is installed separately using SMP/E by following the process documented in the Program Directory, which can be downloaded from the IBM Publications Center:
- Program directory for Advanced Message Security for z/OS Long Term Support Release V9.0.0 (GI13-3388)
- Program directory for Advanced Message Security for z/OS Continuous Delivery Release V9.0.x (GI13-3398)
When we have completed the SMP/E installation, it provides the SDRQAUTH library which contains the Advanced Message Security for z/OS enablement module. You must make the enablement module available for processing during queue manager startup, either by adding to the system linklist or LPA, or for individual queue managers, by including in the STEPLIB concatenation.
The enablement module can be used with either a Long Term Support release or Continuous Delivery release of IBM MQ for z/OS to activate the Advanced Message Security for z/OS functions.
Procedure
- Install Advanced Message Security for z/OS using SMP/E. When installing Advanced Message Security for z/OS, you must follow the instructions in the appropriate Program Directory.
- Enable Advanced Message Security for z/OS separately for each queue manager. Completing the additional customization tasks described in Customizing IBM MQ for z/OS. The following tasks are relevant when adding AMS support to a queue manager:
You also need to configure certificates and policies, which are described in
- Task 2: APF authorize the IBM MQ load libraries
- Task 3: Update the z/OS link list and LPA
- Task 4: Update the z/OS program properties table
- Task 13: Customize the initialization input data sets
- Task 17: Tailor your system parameter module
- Task 23: Create procedures for Advanced Message Security
- Task 24: Set up the started task user Advanced Message Security
- Task 25: Grant RACDCERT permissions to the security administrator for Advanced Message Security
- Task 26: Grant users resource permissions for Advanced Message Security
Results
Advanced Message Security component has been installed successfully.