Chapter 11. Hardware Management Console and Support Elements
425
11.5.13 Cryptographic support
This section lists the cryptographic management and control functions that are available in
the HMC and the SE.
Cryptographic hardware
z13s servers include both standard cryptographic hardware and optional cryptographic
features for flexibility and growth capability.
The HMC/SE interface provides the following capabilities:
Defining the cryptographic controls
Dynamically adding a Crypto feature to a partition for the first time
Dynamically adding a Crypto feature to a partition that already uses Crypto
Dynamically removing a Crypto feature from a partition
The Crypto Express5S, a new Peripheral Component Interconnect Express (PCIe)
cryptographic coprocessor, is an optional z13s exclusive feature. Crypto Express5S provides
a secure programming and hardware environment on which crypto processes are run. Each
Crypto Express5S adapter can be configured by the installation as a Secure IBM Common
Cryptographic Architecture (CCA) coprocessor, a Secure IBM Enterprise Public Key
Cryptography Standards (PKCS) #11 (EP11) coprocessor, or an accelerator.
When EP11 mode is selected, unique Enterprise PKCS #11 firmware is loaded into the
cryptographic coprocessor. It is separate from the CCA firmware that is loaded when a CCA
coprocessor is selected. CCA firmware and PKCS #11 firmware cannot coexist at the same
time in a card.
The Trusted Key Entry (TKE) Workstation with smart card reader feature is required to
support the administration of the Crypto Express5S when configured as an Enterprise
PKCS #11 coprocessor.
To support the new Crypto Express5S card, the Cryptographic Configuration window was
changed to support the following card modes:
Accelerator mode (CEX5A)
CCA Coprocessor mode (CEX5C)
PKCS #11 Coprocessor mode (CEX5P)
The Cryptographic Configuration window also has the following updates:
Support for a Client-Initiated Self-test (CIS) for Crypto running EP11 Coprocessor mode.
TKE commands are always permitted for EP11 mode.
The Test RN Generator function was modified and generalized to also support CIS,
depending on the mode of the crypto card.
The Crypto Details window was changed to display the crypto part number.
Support is now provided for up to four User Defined Extensions (UDX) files. Only UDX
CCA is supported for z13s servers.
UDX import now supports importing from DVD only.
Summary of Contents for z13s
Page 2: ......
Page 3: ...International Technical Support Organization IBM z13s Technical Guide June 2016 SG24 8294 00 ...
Page 24: ...THIS PAGE INTENTIONALLY LEFT BLANK ...
Page 164: ...136 IBM z13s Technical Guide ...
Page 226: ...198 IBM z13s Technical Guide ...
Page 256: ...228 IBM z13s Technical Guide ...
Page 414: ...386 IBM z13s Technical Guide ...
Page 464: ...436 IBM z13s Technical Guide ...
Page 476: ...448 IBM z13s Technical Guide ...
Page 498: ...470 IBM z13s Technical Guide ...
Page 502: ...474 IBM z13s Technical Guide ...
Page 568: ...540 IBM z13s Technical Guide ...
Page 578: ...550 IBM z13s Technical Guide ...
Page 584: ...556 IBM z13s Technical Guide ...
Page 585: ...ISBN 0738441678 SG24 8294 00 1 0 spine 0 875 1 498 460 788 pages IBM z13s Technical Guide ...
Page 586: ......
Page 587: ......
Page 588: ...ibm com redbooks Printed in U S A Back cover ISBN 0738441678 SG24 8294 00 ...