Table
3-7.
LPAR
&
Crypto
Assignments
(continued)
LPAR
&
Crypto
Use
Usage
Domain
Assignment
Logical
Partition
Assignment
Backup
Required?
Specify
2nd
Logical
Partition
ACM17
Prod
SSL
&
secure
3
UD=4
A00
&
X05
A01
&
X06
ACM18
Test
SSL
&
secure
3
UD=5,
2
4
A00
&
X02
A04
&
X05
ACM19
Test
SSL
only
UD=6
A00
A04
ACM5VM
Prod
VM
UD=7,
8,
9,
10
A07
&
X05
Notes:
1.
LPAR
ACME0
and
ACME1
both
use
Accelerator
cards
A00
and
A04,
however,
they
use
two
different
Usage
Domains
on
these
cards.
2.
LPAR
ACME0
and
ACME3
both
use
Usage
Domain
0,
but
they
use
them
on
different
accelerator
cards,
A00/A04
and
A01/A07.
3.
LPAR
ACM17
and
ACM18
both
use
Crypto
Coprocessor
X05,
but
they
use
different
Usage
Domains
on
those
cards,
so
there
is
no
conflict.
4.
ACM18
has
two
Usage
Domains
assigned,
but
only
one
can
be
used
at
a
time.
Normally,
this
TEST
LPAR
will
provide
SSL
and
Secure
support
for
the
Test
environment
using
Usage
Domain
5
on
crypto
accelerator
cards
A00
and
A01,
and
crypto
coprocessor
cards
X05
and
X06.
By
defining
this
LPAR
with
access
to
Usage
Domain
2
it
can
be
a
backup
LPAR
for
ACME2.
If
and
when
there
is
a
problem
with
LPAR
ACME2,
that
operating
system
can
be
IPL’d
in
this
LPAR,
with
the
ICSF
started
task
pointing
to
UD=2,
and
it
will
be
able
to
access
the
master
keys
for
ACME2,
which
are
stored
in
Usage
Domain
2
on
X02
and
X05.
It
is
very
important
to
make
the
correct
Crypto
number
assignments
in
the
Cryptographic
Candidate
List
for
each
of
these
logical
partitions
to
avoid
assignment
conflicts.
Installation
of
a
Cryptographic
Adapter
requires
the
IBM
CP
Assist
for
Crpytographic
Functions
(CPACF)
feature.
See
the
z/OS
ICSF
Application
Programmer’s
Guide
and
the
z/OS
ICSF
System
Programmer’s
Guide
for
complete
information.
Cryptographic
Online
List
The
Cryptographic
Online
List
identifies
the
Cryptographic
numbers
that
are
automatically
brought
online
during
logical
partition
activation.
The
Cryptographic
numbers
selected
in
the
Online
List
must
also
be
selected
in
the
Candidate
List.
After
partition
activation,
installed
Cryptographic
features
that
are
in
the
partition
Cryptographic
Candidate
list
but
not
in
the
Cryptographic
Online
List
are
in
a
configured
off
state
(Standby).
They
can
be
later
configured
on
to
the
partition
from
the
Support
Element
using
the
Configure
On/Off
option
in
the
Crypto
Service
Operations
task
list.
When
the
partition
is
activated,
an
error
condition
is
not
reported
if
the
Cryptographic
number
selected
in
the
Online
list
is
not
installed
in
the
system.
The
Cryptographic
number
is
ignored
and
the
activation
process
continues.
If
a
Cryptographic
number
selected
in
the
Online
list
has
been
configured
off
to
the
partition,
it
is
automatically
configured
back
on
during
the
next
partition
activation.
3-80
PR/SM
Planning
Guide
Summary of Contents for Z9
Page 1: ...System z9 Processor Resource Systems Manager Planning Guide SB10 7041 03...
Page 2: ......
Page 3: ...System z9 Processor Resource Systems Manager Planning Guide SB10 7041 03...
Page 12: ...x PR SM Planning Guide...
Page 18: ...xvi PR SM Planning Guide...
Page 26: ...xxiv PR SM Planning Guide...
Page 54: ...1 28 PR SM Planning Guide...
Page 126: ...2 72 PR SM Planning Guide...
Page 220: ...4 8 PR SM Planning Guide...
Page 232: ...5 12 PR SM Planning Guide...
Page 250: ...B 16 PR SM Planning Guide...
Page 266: ...D 10 PR SM Planning Guide...
Page 272: ...X 6 PR SM Planning Guide...
Page 273: ......
Page 274: ...Printed in USA SB10 7041 03...