Two cryptographic hardware choices are available for use on various systems:
CCF is a standard component on z900 and a no-cost option for z800. On z800 and z900 systems, ICSF requires CCF.
CPACF is a standard component on z9 and z10 and a no-cost option for z890 and z990.
Other available cryptographic hardware components might do not necessarily improve encryption performance, as described in the following list:
These co-processors, which provide secure key storage, hardware hashing, and SSL support.
These accelerators provide high performance SSL assistance.
Note: CA View does not require the use of the Cryptographic Express2 coprocessor (CEX2C). To run ICSF without a CEX2C co-processor, you need ICSF release FMID HCR7751or higher.
If you are running an older release of ICSF, you must purchase a CEX2C co-processor, because previous releases of ICSF require that hardware to initialize the CKDS data set.
IEBGENER cannot be used to print a report from a backup tape because data is now stored in encrypted format.
If you use z/OS software encryption and decryption, the time the CPU uses to encrypt or decrypt data increases the CPU time consumed by the job or started task.
Our tests have shown that encryption using the Crypto Assist Facility (CPACF) has the least amount of overhead. We experienced an increase of 1/10 of a CPU second for every million lines archived or browsed.
|
Copyright © 2015 CA Technologies.
All rights reserved.
|
|