When SecureKeysOnly=Y is set in the StartupOptions section of parmlib, you may optionally disable Special Secure Mode in ICSF by setting SSM(NO) in the ICSF parmlib. CA does not recommend disabling Special Secure Mode when SecureKeysOnly is set to either N or K in the StartupOptions section. When Special Secure Mode is disabled, ICSF does not allow keys stored in the CKDS to be accessed as clear keys. Because of this, CA Tape Encryption cannot migrate keys out of the CKDS and cannot use keys in the CKDS for services that require clear keys. Therefore, in addition to following the CA Tape Encryption guidelines for disaster recovery of the BES database, you must also follow the IBM guidelines for disaster recovery of the CKDS when running with Special Secure Mode disabled in ICSF.
| Copyright © 2011 CA. All rights reserved. | Tell Technical Publications how we can improve this information |