There are two formats of the TKDS: original and KDSR. Both formats use the same LRECL. The KDSR format provides support for metadata for each record including tracking usage of the record. To convert the original format TKDS to KDSR format, see Migrating to the KDSR format key data set.
For secure PKCS #11 support, the TKDS must be initialized. Support to INITIALIZE TKDS and UPDATE TKDS is available in the Master Key Management Panels.
For information on managing and sharing the TKDS in a sysplex environment, see z/OS Cryptographic Services ICSF Administrator's Guide.
Access authorization of the new callable services will be determined via SAF calls. No support will be provided for invocation of an installation security exit for these new services. The CSFSERV class controls access to the ICSF PKCS #11 callable services.