Previous Topic: Secure Keys Selectively

Next Topic: How CA Tape Encryption for CA Disk Works

When ICSF is Required

The following table indicates the algorithms and functionality of CA Tape Encryption and whether they require ICSF, and the applicable hardware platforms.

Note: ICSF is always required if the CKDS is used to store keys.

Functionality

z800 and z900

z890 and z990

Z9

DES

Yes

No

No

3DES

Yes

No

No

AES128

No

No

No

AES192

No

No

No

AES256

No

No

No

MD5

No

No

No

SHA-1

No

No

No

SHA-256

No

No

No

B2B (RSA)

Depends on symmetric algorithm

Depends on symmetric algorithm

Depends on symmetric algorithm

B2B (Codebook)

Depends on symmetric algorithm

Depends on symmetric algorithm

Depends on symmetric algorithm

SecureKeysOnly

Yes

Yes

Yes

FIPS=ENABLED

No

No

No

Note: For B2B tapes using RSA or code books, ICSF may or may not be required, depending on the symmetric key algorithm specified in the description field of the DFSMS data class.

For more information about specifying these algorithms and functions, see the Configuration Guide.