Expert Guide, News Start updating now: Most recent IBM EKMF Workstation Update to 10.3.2

André Wild — 05. Jul 2024
Reading time: 1:15 minutes

IBM EKMF Workstation Update auf 10.3.2: Unified Key Orchestrator for IBM z/OS

The IBM EKMF Workstation Update 10.3.2 is released - here you can find the workaround to keep you going.

EKMF Workstation Update to 10.3.2

 

IBM's Enterprise Key Management Foundation (EKMF) is a comprehensive encryption key management solution that ensures security, compliance and efficiency for organisations of all sizes.

 
With the latest version of EKMF, provided by IBM, IBM introduces the signing of updates. This involves extracting the certificate from the update file and verifying the fingerprint against the fingerprint provided.

EKMF Update-Utiltiy update

The update wizard provided by IBM must be started as root.

Using the Applications menu:

Applications -> IBM EKMF Utility -> IBM EKMF Update

Alternatively via the terminal:

sudo $(command -v ekmf-update)

The update utility must first be updated via the selection dialogue. These changes are required to install and verify the certificate.

EKMF-Utility-Tool-Update-10.3.2.ekmf

SHA256 hash by IBM

3466c8eea013895317b03fd61f78aeb2e7af6f83233dfc76cf444bb05a8401ff  EKMF-Utility-Tool-Update-10.3.2.ekmf

Update to 10.3.2

Once the update utility has been updated, the actual EKMF update to version 10.3.2 can be installed.

To do this, start the EKMF update utility again. (The first update only updates the update wizard and the actual update to EKMF 10.3.2 is only installed with the second update. It must therefore also be started twice. This is because IBM has decided to sign future updates.)

Using the Applications menu:

Applications -> IBM EKMF Utility -> IBM EKMF Update

Alternatively via the terminal:

sudo $(command -v ekmf-update)

The ekmf-10.3.2-update.ekmf is now selected via the selection dialogue.

Next, the fingerprint is displayed and must be checked against the fingerprint from the EKMF-Update-Certificate-fingerprint.txt file.

SHA1 Fingerprint=C3:F8:E5:FA:B2:D7:47:D1:6D:F3:51:2E:B8:8A:B7:7E:96:BA:19:0A
Als nächstes wird der Fingerabdruck angezeigt und muss gegen den Fingerabdruck aus der Datei EKMF-Update-Certificate-fingerprint.txt geprüft werden.

The certificate is then extracted from the update file and copied to /etc/ssl/certs/IBM_Codesign.crt.

Danach wird das Zertifikat aus der Update-Datei extrahiert und nach /etc/ssl/certs/IBM_Codesign.crt kopiert.

The update files will now be checked and the following message will appear:

Danach wird das Zertifikat aus der Update-Datei extrahiert und nach /etc/ssl/certs/IBM_Codesign.crt kopiert.

The EKMF update will then start as usual.

Known problems and workarounds

Problem

The EKMF update utility has been successfully updated, but the installation of EKMF v10.3.2 ends with the following error message:

Das EKMF Update-Utility wurde erfolgreich aktualisiert, aber die Installation von EKMF v10.3.2 endet mit folgender Fehlermeldung

Solution

The file ekmf-10.3.2-update.ekmf must be saved in a path without spaces. The provided files may be extracted into a folder named "EKMF Release 10.3.2" after the download. This folder contains spaces, which can cause issues.

Description

The new ekmf-update utility uses the update file to extract the certificate. Unfortunately, the paths were not set in double quotes, which leads to word separation in bash. This causes the installation of the certificate to fail.

André Wild

Do you have questions about EKMF or related topics? Simply send us an e-mail.

André Wild, Senior Consultant
Phone +4917254114229

You were interested in this, then you may also be interested in...