This topic describes the servers on which the cryptographic hardware
features are available.
IBM zEnterprise 196 (z196)
The z196 provides constraint relief and addresses various customer
demands. It has several cryptographic features.
- CP Assist for Cryptographic Functions is implemented on every processor.
SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512
secure hashing is directly available to application programs.
- Feature code 3863, CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement – enables
clear key DES and TDES instructions on all CPs. AES 128-bit,
AES 192-bit and AES 256-bit support is also available.
- Feature code 0864, Crypto Express3 Feature –
optional, and only available if you have feature 3863, CPACF DES/TDES
Enablement installed. The z10 EC and z10 BC can support a maximum
of 8 features. Each feature code has two coprocessors/accelerators.
IBM System z10 Enterprise Class and IBM System z10 Business Class (z10 BC)
The IBM System z10 Enterprise Class and IBM System z10 Business Class provide constraint
relief and addresses various customer demands. It has several cryptographic
features.
- CP Assist for Cryptographic Functions is implemented on every processor.
SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512
secure hashing is directly available to application programs.
- Feature code 3863, CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement – enables
clear key DES and TDES instructions on all CPs. AES 128-bit,
AES 192-bit and AES 256-bit support is also available.
- Feature code 0863, Crypto Express2 Feature –
optional, and only available if you have feature 3863, CPACF DES/TDES
Enablement installed. The z10 EC and z10 BC can support a maximum
of 8 features. Each feature code has two coprocessors/accelerators.
- Feature code 0864, Crypto Express3 Feature –
optional, and only available if you have feature 3863, CPACF DES/TDES
Enablement installed. The z10 EC and z10 BC can support a maximum
of 8 features. Each feature code has two coprocessors/accelerators.
IBM System z9 Business Class (z9 BC)
The IBM System z9 BC provides constraint relief and addresses various
customer demands. It has several cryptographic features.
- CP Assist for Cryptographic Functions is implemented on every processor.
SHA-1, SHA-224 and SHA-256 secure hashing is directly
available to application programs.
- Feature code 3863, CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement – enables
clear key DES and TDES instructions on all CPs. In addition, ICSF supports
hardware implementation of AES 128-bit keys and software
implementation of AES 192-bit and AES 256-bit key
lengths.
- Feature code 0863, Crypto Express2 Feature –
optional, and only available if you have feature 3863, CPACF DES/TDES
Enablement installed. The IBM System z9 BC can support a maximum of
8 features. Each feature code has two coprocessors/accelerators.
IBM System z9 Enterprise Class (z9 EC)
The IBM System z9 EC provides constraint relief and addresses various
customer demands. It has several cryptographic features.
- CP Assist for Cryptographic Functions is implemented on every processor.
SHA-1, SHA-224 and SHA-256 secure hashing is directly
available to application programs.
- Feature code 3863, CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement – enables
clear key DES and TDES instructions on all CPs. In addition, ICSF supports
hardware implementation of AES 128-bit keys and software
implementation of AES 192-bit and AES 256-bit key
lengths.
- Feature code 0863, Crypto Express2 Feature –
optional, and only available if you have feature 3863, CPACF DES/TDES
Enablement installed. The IBM System z9 EC can support a maximum of
8 features. Each feature code has two coprocessors/accelerators.
IBM eServer zSeries 990 (z990)
The IBM zSeries 990 provides constraint relief and
addresses various customer demands. It has several cryptographic features.
- CP Assist for Cryptographic Functions is implemented on every processor.
SHA-1 secure hashing is directly available to application programs.
- Feature code 3863, CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement – enables
clear key DES and TDES instructions on all CPs. In addition, ICSF
supports software implementation of AES.
- Feature code 0862, PCI Cryptographic Accelerator – optional,
and only available if you have feature 3863, CPACF DES/TDES Enablement
installed. The IBM zSeries 990 can support a maximum of 12 PCI Cryptographic Accelerators. Each feature
code has two coprocessors.
- Feature code 0868, PCI X Cryptographic Coprocessor – optional,
and only available if you have feature 3863, CPACF DES/TDES Enablement
installed. The IBM zSeries 990 can support a maximum of 4 PCIXCCs.
Each feature code has one coprocessor.
- Feature code 0863, Crypto Express2 Coprocessor – optional,
and only available if you have feature 3863, CPACF DES/TDES Enablement
installed. The IBM zSeries 990 can support a maximum of 16 CEX2Cs.
Each feature code has two coprocessors.
Note:
You can have a maximum of 6 PCICA features (12
cards), 4 PCIXCC features (4 cards) and 16 CEX2Cs (8 features),
with maximum number of 8 installed features.
IBM eServer zSeries 890 (z890)
The IBM zSeries 890 provides constraint relief and
addresses various customer demands. It has several cryptographic features.
- CP Assist for Cryptographic Functions are implemented on every processor.
SHA-1 secure hashing is directly available to application programs.
- Feature code 3863, CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement – enables
clear key DES and TDES instructions on all CPs. In addition, ICSF
supports software implementation of AES.
- Feature code 0862, PCI Cryptographic Accelerator – optional,
and only available if you have feature 3863, CPACF DES/TDES Enablement
installed. The IBM zSeries 890 can support a maximum of 12 PCI Cryptographic Accelerators. Each feature
code has two coprocessors.
- Feature code 0868, PCI X Cryptographic Coprocessor – optional,
and only available if you have feature 3863, CPACF DES/TDES Enablement
installed. The IBM zSeries 890 can support a maximum of 4 PCIXCCs.
Each feature code has one coprocessor.
- Feature code 0863, Crypto Express2 Coprocessor – optional,
and only available if you have feature 3863, CPACF DES/TDES Enablement
installed. The IBM zSeries 890 can support a maximum of 16 CEX2Cs.
Each feature code has two coprocessors.
Note:
You can have a maximum of 6 PCICA features (12
cards), 4 PCIXCC features (4 cards) and 16 CEX2Cs (8 features),
with maximum number of 8 installed features.
IBM eServer zSeries 900 (z900) — Feature Code 800
You can enable these features on this server:
- Cryptographic Coprocessor Feature – one or two cryptographic coprocessors
protected by tamper-detection circuitry and a cryptographic battery
unit.
- Feature code 0861, PCI Cryptographic Coprocessor (PCICC) –
based on the 4758 model 2 standard PCI-bus card package. You must
have at least one Cryptographic Coprocessor Feature on your system with a PCICC. Note that each
feature has two coprocessors.
- Feature code 0862, PCI Cryptographic Accelerator (PCICA). You
must have at least one Cryptographic Coprocessor Feature on your system with a PCICA. Note that
each feature has two coprocessors.
Note:
The IBM zSeries 900 can support a combination of PCI Cryptographic Coprocessors
(maximum of 16) or PCI Cryptographic Accelerators (maximum of 12), but the total must not
exceed 16.
IBM eServer zSeries 800 (z800) — Feature Code 800
These features are available on this server:
- Cryptographic Coprocessor Feature (CCF) – one or two cryptographic
coprocessors protected by tamper-detection circuitry and a cryptographic
battery unit.
- Feature code 0861, PCI Cryptographic Coprocessor (PCICC) –
based on the 4758 model 2 standard PCI-bus card package. You must
have at least one Cryptographic Coprocessor Feature on your system with a PCICC. Note that each
feature has two coprocessors.
- Feature code 0862, PCI Cryptographic Accelerator (PCICA). You
must have at least one Cryptographic Coprocessor Feature on your system with a PCICA. Note that
each feature code has two coprocessors.
Note:
The IBM zSeries 800 can support a combination of PCI Cryptographic Coprocessors
(maximum of 16) or PCI Cryptographic Accelerators (maximum of 12), but the total must not
exceed 16.
|