Stream: Hungaroring
Time: 14:15 - 15:00
Modern mainframe applications run Java and Spring Boot workloads inside CICS Liberty, and those workloads need to connect securely to external REST APIs and Db2. This session shows how to do that the z/OS-native way, using RACF key rings instead of file-based keystores, so certificates and private keys stay managed, audited, and protected. We'll cover Liberty server.xml configuration for inbound mutual TLS (mTLS) against a RACF key ring, and how a Spring Boot microservice makes outbound mTLS calls to external APIs and Db2 using RACF-managed certificates. We'll also walk through the RACF authorizations required and the common pitfalls around certificate chains, key ring permissions, and renewal.
There is currently no attachment for Securing CICS Liberty and it's applications using RACF Keyrings
Reddy has many years of experience as a COBOL programmer and software architect. He is a mainframe moderniser who has worked on CICS Liberty, zDIH and many other new technologies.