If running in a sysplex, see Running in a Sysplex Environment.
The first time you start
ICSF, you must:
- Create a cryptographic key data set (CKDS)
- Create a PKA key data set (PKDS)
- Enter a new DES-MK into each coprocessor (optional)
- Enter a new RSA-MK into each coprocessor (optional)
- Enter a new AES-MK into each CCA Cryptographic coprocessor
that is a CEX2C or later (optional)
- Enter a new ECC-MK into each CCA Cryptographic coprocessor
that is a CEX3C or later (optional)
- Initialize the CKDS
- Initialize the PKDS
When you initialize the CKDS, ICSF creates a header record for
the CKDS and sets any DES or AES master keys in the new master key
registers. When you initialize the PKDS, ICSF creates a header record
for the PKDS and sets any ECC or RSA master keys in the new master
key registers.