Chapter 5. Cryptography 129
Draft Document for Review April 7, 2004 6:15 pm 6947ch05.fm
(1) Requires CPACF enablement
(2) In order to make addition of PCIXCC and PCICA features nondisruptive, the logical partition
must be predefined with the appropriate PCI cryptographic processor number selected in its
candidate list, on the partition image profile.
(3) Not required for Linux
(4) PCIXCC is assigned one PCHID per feature. PCICA is assigned two PCHIDs per feature
(one per accelerator processor).
5.5 Software requirements
Cryptographic support for z990 for OS/390 V2.10, z/OS V1.2 and later is made available as a
Web deliverable.
z990 Cryptographic Support is planned to be available through May 28, 2004. It is a Web
deliverable to provide exploitation support for the CPACF, PCICA, and PCIXCC features on
behalf of OS/390 V2.10, and z/OS V1.2 and later releases. On May 28, 2004 this support is
replaced by z990 and z890 Enhancements to Cryptographic Support.
z990 and z890 Enhancements to Cryptographic Support is planned to be available on
May 28, 2004. It is a Web deliverable to provide exploitation support for CPACF, PCICA, and
PCIXCC features on behalf of OS/390 V2.10, z/OS V1.3, z/OS V1.4, and z/OS V1.5, and in
addition supports the following functions:
Usable for data privacy - encryption and decryption processing XX
Usable for data integrity - hashing and message authentication XX
Usable for financial processes and key management operations X
Crypto performance RMF™ monitoring XX
Requires system master keys to be loaded X
System (master) key storage X
Retained key storage X
Tamper-resistant hardware packaging X
Designed for FIPS 140-2 Level 4 certification X
Supports SSL functions XXX
Supports Linux applications doing SSL handshakes X
RSA functions XX
High performance SHA-1, Hash function X
Clear key DES/T-DES X
Clear key RSA XX
Double length DUKPT support X
Europay Mastercard VISA (EMV) support X
Public Key Decrypt (PKD) support for Zero-Pad option for clear RSA
private keys) XX
Public Key Encrypt (PKE) support for MRP function XX
Functions or Attributes CPACF PCIXCC PCICA