z/OS Cryptographic Services ICSF Application Programmer's Guide
Previous topic | Next topic | Contents | Index | Contact z/OS | Library | PDF


Usage Notes

z/OS Cryptographic Services ICSF Application Programmer's Guide
SA22-7522-16

SAF may be invoked to verify the caller is authorized to use this callable service, the key label, or internal secure key tokens that are stored in the CKDS or PKDS.

If you are using the IBM 3624 PIN and IBM German Bank Pool PIN algorithms, you can supply an unencrypted customer selected PIN to generate a PIN offset.

This table shows the access control points in the ICSF role that control the function of this service.

Table 174. Required access control points for Clear PIN Generate
Rule array keywordsAccess control point
IBM-PIN
IBM-PINO
Clear PIN Generate - 3624
GBP-PINClear PIN Generate - GBP
VISA-PVVClear PIN Generate - VISA PVV
INBK-PINClear PIN Generate - Interbank

If the ANSI X9.8 PIN - Use stored decimalization tables only access control point is enabled in the ICSF role, any decimalization table specified must match one of the active decimalization tables in the coprocessors.

This table lists the required cryptographic hardware for each server type and describes restrictions for this callable service.

Table 175. Clear PIN generate required hardware
ServerRequired cryptographic hardwareRestrictions
IBM eServer zSeries 900Cryptographic Coprocessor FeatureICSF routes this service to a PCI Cryptographic Coprocessor if the control vector of the PIN generating key cannot be processed on the Cryptographic Coprocessor Feature.
IBM eServer zSeries 990

IBM eServer zSeries 890

PCI X Cryptographic Coprocessor

Crypto Express2 Coprocessor

Rule_array keyword GBP-PINO is not supported.
IBM System z9 EC

IBM System z9 BC

Crypto Express2 CoprocessorRule_array keyword GBP-PINO is not supported.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014