z/OS Cryptographic Services ICSF Application Programmer's Guide
Previous topic | Next topic | Contents | Index | Contact z/OS | Library | PDF


Coordinated KDS Administration (CSFCRC and CSFCRC6)

z/OS Cryptographic Services ICSF Application Programmer's Guide
SA22-7522-16

Use the coordinated KDS administration callable service to perform a coordinated CKDS refresh or a coordinated CKDS master key change.

When used for master key change, applications can continue to run CKDS update workloads in parallel, and ICSF guarantees that any dynamic updates will be reflected in the target data set. For coordinated CKDS refresh, you should disable CKDS update workloads when refreshing to a target data set that is different from the currently-active CKDS. This is recommended, because updates occurring to the currently-active CKDS might not be reflected in the target data set. ICSF does not enforce manual disablement of dynamic CKDS updates prior to a coordinated refresh operation, and will itself internally suspend such updates until the coordinated refresh operation completes. Note that the recommendation to disable CKDS updates does not apply to a coordinated refresh when the target data set is the same as the currently-active CKDS. In this case, the updates to the currently-active CKDS are guaranteed to be in the resulting in-storage CKDS when the operation completes.

In a sysplex environment, this callable service enables an application to perform a coordinated sysplex-wide CKDS refresh or CKDS change master key operation from a single ICSF instance.

The callable service name for AMODE(64) invocation is CSFCRC6.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014