Chapter 6. Cryptography 225
6.7 Cryptographic functions comparison
Table 6-4 lists the functions or attributes on z13s servers for the two cryptographic hardware
features. In the table, “X” indicates that the function or attribute is supported.
Table 6-4 Cryptographic functions on z13s servers
Server
supported
z196 Yes Yes Yes Yes
z114 Yes Yes Yes Yes
zEC12 Yes Yes Yes Yes
zBC12 Yes Yes Yes
z13 Yes Yes
z13s Yes Yes
Manage Host
Crypto Module
CEC3C (CCA) Yes Yes Yes Yes
CEX4C (CCA) Yes Yes Yes Yes
CEX4P (EP11) Yes
c
Ye s
c
Ye s
c
Ye s
d
CEX5C (CCA) Yes Yes
CEX5P (EP11) Yes Yes
a. TKE workstation (FC 0842) with LIC 7.3 can be upgraded to TKE tower workstation (FC 0847) with LIC 8.0
or LIC 8.1. The MES generates FC 0894 to add the IBM 4767 adapter.
b. Older smart cards 45D3398 (FC 0884) and 74Y0551 (FC 0884) can be used on TKE workstation with
LIC 8.0 (available from System z10)
c. A Crypto Express4S running in EP11 mode requires smart cards to hold administrator certificates and
master key material. The smart card must be P/N 74Y0551.
d. A Crypto Express4S running in EP11 mode requires smart cards to hold administrator certificates and
master key material. The smart card must be P/N 74Y0551.
Attention: The TKE is unaware of the CPC type where the host crypto module is installed.
That is, the TKE does not care whether a Crypto Express is running on a z196, z114,
zEC12, zBC12, z13, or z13s servers. Therefore, the LIC can support any CPC where the
coprocessor is supported, but the TKE LIC must support the specific crypto module.
Functions or attributes CPACF CEX5C CEX5P CEX5A
Supports z/OS applications using ICSF X X X X
Supports Linux on z Systems CCA applications X X - X
Encryption and decryption using secret-key algorithm - X X -
Provides the highest SSL/TLS handshake
performance
---X
Supports SSL/TLS functions X X - X
Provides the highest symmetric (clear key) encryption
performance
X- - -
Provides the highest asymmetric (clear key)
encryption performance
---X