Cryptographic Configuration Window; Installation Support For Z/Vm Using The Hmc - IBM z13s Technical Manual

Table of Contents

Advertisement

Figure 11-30 shows an example of the Cryptographic Configuration window.
Figure 11-30 Cryptographic Configuration window
The Usage Domain Zeroize task is provided to clear the appropriate partition crypto keys for a
usage domain when you remove a crypto card from a partition. Crypto Express5S in EP11
mode is configured to the standby state after zeroize.
For more information, see IBM z13 Configuration Setup, SG24-8260.
Digitally signed firmware
Critical issues with firmware upgrades are security and data integrity. Procedures are in place
to use a process to digitally sign the firmware update files that are sent to the HMC, the SE,
and the TKE. Using a hash algorithm, a message digest is generated that is then encrypted
with a private key to produce a digital signature.
This operation ensures that any changes that are made to the data are detected during the
upgrade process by verifying the digital signature. It helps ensure that no malware can be
installed on z Systems products during firmware updates. It enables the z13s Central
Processor Assist for Cryptographic Function (CPACF) functions to comply with Federal
Information Processing Standard (FIPS) 140-2 Level 1 for Cryptographic Licensed Internal
Code (LIC) changes. The enhancement follows the z Systems focus on security for the HMC
and the SE.

11.5.14 Installation support for z/VM using the HMC

Starting with z/VM V5R4 and System z10, Linux on z Systems can be installed in a z/VM
virtual machine from HMC workstation media. This Linux on z Systems installation can use
the existing communication path between the HMC and the SE. No external network or extra
network setup is necessary for the installation.
11.5.15 Dynamic Partition Manager
DPM is a z Systems mode of operation that provides a simplified approach to create and
manage virtualized environments, reducing the barriers of its adoption for new and existing
customers. For more information about Dynamic Partition Manager (DPM), see Appendix E.,
"IBM Dynamic Partition Manager" on page 501.
426
IBM z13s Technical Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents