Entering keys by using the dynamic PKDS update services

ICSF provides a set of callable services that allow applications to dynamically update the PKDS. Applications can use the PKDS Key Record Create service to create new records in the PKDS, the PKDS Key Record Write service to write a key token to an existing record, and PKDS Key Record Delete service to remove a record from the PKDS. These dynamic updates affect both the DASD copy of the PKDS currently in use and the in-storage copy. Another service allows an application to retrieve the key token from a record in the in-storage PKDS. That token can be used directly in subsequent CALLs to cryptographic services. For more information on using the dynamic PKDS update services, see z/OS Cryptographic Services ICSF Application Programmer's Guide.