Cryptographic Support - IBM z13s Technical Manual

Table of Contents

Advertisement

11.5.13 Cryptographic support

This section lists the cryptographic management and control functions that are available in
the HMC and the SE.
Cryptographic hardware
z13s servers include both standard cryptographic hardware and optional cryptographic
features for flexibility and growth capability.
The HMC/SE interface provides the following capabilities:
Defining the cryptographic controls
Dynamically adding a Crypto feature to a partition for the first time
Dynamically adding a Crypto feature to a partition that already uses Crypto
Dynamically removing a Crypto feature from a partition
The Crypto Express5S, a new Peripheral Component Interconnect Express (PCIe)
cryptographic coprocessor, is an optional z13s exclusive feature. Crypto Express5S provides
a secure programming and hardware environment on which crypto processes are run. Each
Crypto Express5S adapter can be configured by the installation as a Secure IBM Common
Cryptographic Architecture (CCA) coprocessor, a Secure IBM Enterprise Public Key
Cryptography Standards (PKCS) #11 (EP11) coprocessor, or an accelerator.
When EP11 mode is selected, unique Enterprise PKCS #11 firmware is loaded into the
cryptographic coprocessor. It is separate from the CCA firmware that is loaded when a CCA
coprocessor is selected. CCA firmware and PKCS #11 firmware cannot coexist at the same
time in a card.
The Trusted Key Entry (TKE) Workstation with smart card reader feature is required to
support the administration of the Crypto Express5S when configured as an Enterprise
PKCS #11 coprocessor.
To support the new Crypto Express5S card, the Cryptographic Configuration window was
changed to support the following card modes:
Accelerator mode (CEX5A)
CCA Coprocessor mode (CEX5C)
PKCS #11 Coprocessor mode (CEX5P)
The Cryptographic Configuration window also has the following updates:
Support for a Client-Initiated Self-test (CIS) for Crypto running EP11 Coprocessor mode.
TKE commands are always permitted for EP11 mode.
The Test RN Generator function was modified and generalized to also support CIS,
depending on the mode of the crypto card.
The Crypto Details window was changed to display the crypto part number.
Support is now provided for up to four User Defined Extensions (UDX) files. Only UDX
CCA is supported for z13s servers.
UDX import now supports importing from DVD only.
Chapter 11. Hardware Management Console and Support Elements
425

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents