IBM z13s Technical Manual page 245

Table of Contents

Advertisement

PKA Translate UDX function into CCA
UDX is custom code that allows the client to add unique operations and extensions to the
CCA firmware. Certain UDX functions are integrated into the base CCA code over time to
accomplish the following tasks:
Removes headaches and pain points that are associated with UDX management and
currency.
Popular UDX functions are made available to a wider audience to encourage adoption.
UDX is integrated into the base CCA code to support translating an external RSA Chinese
Remainder Theorem key into new formats. These new formats use tags to identify key
components. Depending on which new rule array keyword is used with the PKA Key Translate
callable service, the service TDES encrypts those components in either CBC or ECB mode.
In addition, AES CMAC Support is delivered.
This function has the following requirements:
Hardware requirements:
– z13s servers and Crypto Express5S with CCA V5.2 firmware
– z13 servers and Crypto Express5S with CCA V5.0 or later firmware
– zEC12 or zBC12 servers and Crypto Express4S with CCA V4.4 firmware
– zEC12, zBC12, z196 or z114 servers and Crypto Express3 with CCA V4.4 firmware
Software requirements:
– z/OS V2.2
– z/OS V2.1 or z/OS V1.13 with the Cryptographic Support for z/OS V1R13-z/OS V2R1
web deliverable (FMID HCR77A1) with PTFs
– z/OS V2.1 (FMID HCR77A0) with PTFs
– z/OS V1.13 with the Cryptographic Support for z/OS V1R13-z/OS V2R1 web
deliverable (FMID HCR77A1) with PTFs
– z/OS V1.12 or z/OS V1.13 with the Cryptographic Support for z/OS V1R12-V1R13 web
deliverable (FMID HCR77A0) with PTFs
– z/OS V1.12 or V1.13 with the Cryptographic Support for z/OS V1R11-V1R13 web
deliverable (FMID HCR7790) with PTFs
– z/VM Version 6.2, and Version 6.3 with PTFs for guest use
Verb Algorithm Currency
Verb Algorithm Currency is a collection of CCA verb enhancements related to customer
requirements, with the intent of maintaining currency with cryptographic algorithms and
standards. It is intended for customers wanting to maintain the latest cryptographic
capabilities. It provides these functions:
Secure key support AES GCM encryption
New Key Check Value (KCV) algorithm for service CSNBKYT2 Key Test 2
New key derivation options for CSNDEDH EC Diffie-Hellman service
Here are the requirements for this function:
Hardware requirements:
– z13s or z13 servers and Crypto Express5S with CCA V5.2 firmware
Chapter 6. Cryptography
217

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents