0000699: SAF-KeyRing support
Add Racf-KeyRing support for example PGP (conversion/encryption)
http://www-01.ibm.com/support/knowledgecenter/SSLTBW_2.1.0/com.ibm.zos.v2r1.ichd100/gplfrd.htm [^]

The r_datlib service can be used to read entries from the key ring.

The key ring can contain clear key pairs, PKCS#11 tokens, ICSF label for EP11 tokens or CCA keys.

The SAF key ring support must be implemented on top of the P11 and CCA support, and simplifies siply the access to the key/token label.

The FKME for asymetric key exchange and signing used for FLAM5 archive, OpenPGP files or other encryption cabebilities must be extent to determine the current active key of the declared user based on the assigned SAF key ring.

This solution must be combatible with RACF, ACF2, Top Secret and other security server.
This support makes key management very complex. It was mainly planed to get the keys managed with DKMS/EKMF. For DKMS/EKMF a direct support over DKMS/EKMF-API and UKDS7 is now planed. Based on that this support will only implemented on customer request.

Asspecial for OpenPGP a SUB-CA key in the PKDS is require as prerequisit to translate OpenPGP KeyFiles (Certificates) in X509 Certificates for SAF-KeyRings. This signature verification over the PGP key to generate then the signature over the X509 certificate, makes the whole process very complex.

It will be simpler and more secure, if the keys only managed by DKMS/EKMF and used by FLAM over ICSF/CCA, PKCS11 or some ohter supported HSM of DKMS/EKMF.
Is not required anymore