z/OS Cryptographic Services ICSF Administrator's Guide
Previous topic | Next topic | Contents | Index | Contact z/OS | Library | PDF


Allocating Resources on CCF Systems

z/OS Cryptographic Services ICSF Administrator's Guide
SA22-7521-17

You use the Hardware Master Console tasks to enable various cryptographic functions for an LP. To assign a control domain index and usage domain index and initially enable cryptographic functions for an LP, use the Crypto page of the Customize Activation Profiles task. On the Crypto page you can enable these functions to the LP:

  • Public key algorithm (PKA) function
  • Cryptographic functions
    • Special secure mode
    • Public key secure cable (PKSC) and Integrated Cryptographic Service Facility (ICSF)
      • Modify authority (only enabled in one LPAR partition at a time)
      • Query signature controls
      • Query transport controls

These functions are hierarchically applied. For instance, if you do not enable cryptographic functions for the LP, you cannot enable any of the functions below it on the list. To enable basic ICSF functions, you must select these parameters on the crypto page:

  • Usage domain index

    The number you select for usage domain index must match the domain number that is entered in the installation options data set for this LP.

  • Enable cryptographic functions

  • Enable public key secure cable (PKSC) and Integrated Cryptographic Service Facility (ICSF)

Once an LP is activated, you can then use the Change LPAR Crypto task to change the cryptographic functions that are enabled for that LP. This task has a page for each LP.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014