z/OS Cryptographic Services ICSF Administrator's Guide
Previous topic | Next topic | Contents | Index | Contact z/OS | Library | PDF


Entering system keys into the cryptographic key data set (CKDS)

z/OS Cryptographic Services ICSF Administrator's Guide
SA22-7521-17

The ICSF CKDS has several sets of system keys. These are the keys with labelname of X'00' and are installed during CKDS initialization. The system keys are required in the CKDS. Other keys are optional; however, their absence will affect functions in many services.

Notes:
  1. FMID HCR7780 introduced a new variable-length record format for CKDS records. When a variable-length CKDS is initialized on a non-CCF system, no system keys are written to the CKDS. A variable-length CKDS that was converted from a fixed-length CKDS will have any system keys of the original CKDS.
  2. The NOCV, ANSI and Extended Systems keys are not required on a z990, z890, z9 EC, z9 BC, z10 EC, z10 BC, or z196 system with a PCIXCC, CEX2C, or CEX3C.
Note:

If the system keys are not in the CKDS, an 18F abnormal end with reason code X'A1' can occur. If the ANSI, NOCV enablement, or the ESYS keys are not in the CKDS, an 18F abnormal end with reason code X'A3' can occur.

This is a summarization of where the keys are used:

  • Required System Keys

    These keys are used to validate CKDS entries and used in many services. These keys are required.

  • NOCV-enablement Keys
    • These keys are needed for all services where NOCV key-encrypting keys are required. See z/OS Cryptographic Services ICSF Application Programmer’s Guide for more information.
    • These keys are needed in CSNBKGN and KGUP where replicated keys are generated, that is, where key length of SINGLE is specified for double-length keys.
    • These keys are used during verification pattern generation on a CDMF-only system.
    • These keys are used by CSNBSBC on a CDMF-only system.
    • These keys are used during CKDS conversion.
    • These keys are required to export and import double-length DATAM and DATAMV keys.
  • ANSI System Keys
    • These keys are used by CSNBSBD on a CDMF-only system.
    • These keys are used when installing the extended system keys (ESYS) on the CKDS initialization panel.
    • These keys are needed for key part import services.
    • These keys are required for key test service CSNBKYT if there are no PCICCs active.
    • These keys are required to generate double-length DATAM and DATAMV keys in the importable form.
  • Extended System Keys

    These keys are required for symmetric key export if there are no PCICCs active.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014