PKZIP /Securezip™ for Zseries
Total Page:16
File Type:pdf, Size:1020Kb
PKZIP®/SecureZIP™ for zSeries (OS/390 and z/OS) User’s Guide SZZU-V8R2000 PKWARE Inc. PKWARE Inc. 648 N Plankinton Avenue, Suite 220 Milwaukee, WI 53203 Sales: 937-847-2374 Sales - Email: [email protected] Support: 937-847-2687 Support - http://www.pkware.com/business_and_developers/support Fax: 414-289-9789 Web Site: http://www.pkware.com 8.2 Edition (2005) SecureZIP for zSeries™, PKZIP for zSeries™, PKZIP for MVS™, SecureZIP for iSeries™, PKZIP for iSeries™, PKZIP for OS/400™, PKZIP for UNIX™, SecureZIP for Windows™, and PKZIP for Windows™ are just a few of the many members in the PKZIP® family. PKWARE Inc. would like to thank all the individuals and companies -- including our customers, resellers, distributors, and technology partners -- who have helped make PKZIP® the industry standard for Trusted ZIP solutions. PKZIP® enables our customers to efficiently and securely transmit and store information across systems of all sizes, ranging from desktops to mainframes. This edition applies to the following PKWARE Inc. licensed programs: PKZIP for zSeries™ (Version 8, Release 2, 2005) SecureZIP™ for zSeries (Version 8, Release 2, 2005) SecureZIP™ for zSeries Reader (Version 8, Release 2, 2005) SecureZIP™ for zSeries SecureLink (Version 8, Release 2, 2005) PKZIP(R) is a registered trademark of PKWARE(R) Inc. SecureZIP is a trademark of PKWARE(R) Inc. Other product names mentioned in this manual may be a trademark or registered trademarks of their respective companies and are hereby acknowledged. Any reference to licensed programs or other material, belonging to any company, is not intended to state or imply that such programs or material are available or may be used. The copyright in this work is owned by PKWARE Inc., and the document is issued in confidence for the purpose only for which it is supplied. It must not be reproduced in whole or in part or used for tendering purposes except under an agreement or with the consent in writing of PKWARE Inc., and then only on condition that this notice is included in any such reproduction. No information as to the contents or subject matter of this document or any part thereof either directly or indirectly arising there from shall be given or communicated in any manner whatsoever to a third party being an individual firm or company or any employee thereof without the prior consent in writing of PKWARE Inc. Copyright © 1989 - 2005 PKWARE Inc. All rights reserved. Contents PREFACE............................................................................................................. 1 Notices.........................................................................................................................1 About this Manual.......................................................................................................1 Conventions Used in This Manual ............................................................................3 PKZIP and SecureZIP Manuals..................................................................................3 Related Publications ..................................................................................................4 Related Information on the Internet..........................................................................5 User Help and Contact Information ..........................................................................5 1 AN INTRODUCTION TO PKZIP AND SECUREZIP FOR ZSERIES ............ 6 Data Compression......................................................................................................7 ZIP Archives ................................................................................................................7 Cyclic Redundancy Check.........................................................................................8 Distinctive Features of PKZIP and SecureZIP for zSeries......................................8 Distinctive Features of SecureZIP for zSeries.........................................................9 Encryption Using Passwords and/or Digital Certificates.....................................10 Cross Platform Compatibility ..................................................................................10 2 INTRODUCTION TO DATA SECURITY ...................................................... 12 SecureZIP for zSeries Security Basics...................................................................12 Operating System Levels........................................................................................13 Digital Certificate Formats.......................................................................................13 SecureZIP for Windows Compatibility.....................................................................13 General Information to Help You Get Started.........................................................14 How do we activate MASTER_RECIPIENT Contingency Keys? ...........................14 Encryption .................................................................................................................17 Authentication...........................................................................................................17 iii Data Integrity...........................................................................................................18 Digital Signature Validation.....................................................................................18 Digital Signature Source Validation ........................................................................19 Public-Key Infrastructure and Digital Certificates ................................................19 Public-Key Infrastructure (PKI) ...............................................................................19 x.509 .......................................................................................................................20 Digital Certificates ...................................................................................................20 Certificate Authority (CA) ........................................................................................20 Private Key..............................................................................................................20 Public Key ...............................................................................................................21 Certificate Authority and Root Certificates..............................................................21 Setting Up Stores for Digital Certificates on zOS .................................................21 Setting Up the Certificate Stores.............................................................................21 Updating the Certificate Stores ...............................................................................23 Types of Encryption Algorithms .............................................................................23 FIPS 46-3, Data Encryption Standard (DES)..........................................................23 Triple DES Algorithm (3DES)..................................................................................24 Advanced Encryption Standard (AES)....................................................................24 Comparison of the 3DES and AES Algorithms.......................................................24 RC4 .........................................................................................................................25 Key Management ......................................................................................................25 Passwords and PINS................................................................................................26 Recipient Based Encryption....................................................................................26 Random Number Generation...................................................................................26 Integrity of Public and Private Keys .......................................................................27 3 PKZIP AND SECUREZIP FOR ZSERIES RELEASE INFORMATION........ 28 Release Summary.....................................................................................................28 New Products..........................................................................................................28 New Features..........................................................................................................28 New Commands and Defaults ................................................................................31 Command Changes ................................................................................................34 Message Changes ..................................................................................................36 Enhancements for Secure Data..............................................................................36 Restrictions for PKZIP and SecureZIP for zSeries................................................36 Region Size and Storage..........................................................................................38 SMS Dataclass Considerations...............................................................................39 Note for users of PKZIP for MVS and PKZIP for zSeries 5.6 .................................40 Reserved DDNAMEs.................................................................................................40 SYSPRINT ..............................................................................................................41 PKSPRINT ..............................................................................................................41