z/OS Cryptographic Services ICSF Administrator's Guide
Previous topic | Next topic | Contents | Index | Contact z/OS | Library | PDF


Callable services

z/OS Cryptographic Services ICSF Administrator's Guide
SA22-7521-17

These callable services can be used on a system without coprocessors with an initialized CKDS. The key management services can only be used to manage clear keys, encrypted keys can not be managed in this configuration.

  • Key record create (CSNBKRC) and key record create2 (CSNBKRC2)
  • Key record write (CSNBKRW) and key record write2 (CSNBKRW2)
  • Key record delete (CSNBKRD)
  • Key record read (CSNBKRR) and key record read2 (CSNBKRR2)

    Key record read will not return a clear key token to the caller unless the caller is in supervisor state or system key.

These services support labels for the key identifier:

  • Symmetric key decipher (CSNBSYD)
  • Symmetric key encipher (CSNBSYE)
  • Symmetric MAC generate (CSNBSMG)
  • Symmetric MAC verify (CSNBSMV)

These services do not require a coprocessor:

  • Key token build (CSNBKTB)
  • One way hash (CSNBOWH)
  • MDC generate (CSNBMDG)

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014