CEX7S / 4769 Ordering
This page provides information on how to order the IBM CEX7S / 4769 HSM.
Order HSM
- IBM Z® family z15® mainframes, either on z/OS® or Linux® on IBM Z operating systems, ordered as a Crypto feature code (FC) 0898 or 0899 – Crypto Express 7S (CEX7S).
- x64 as an IBM Z machine type-model (MTM), on Red Hat® Enterprise Linux (RHEL) 64-bit operating systems. Smart cards are required to manage the IBM 4769. See Order Smart Cards and Readers for ordering smart cards and smart card readers.
- IBM Power Systems™ POWER10® servers, either on IBM AIX®, IBM i®, or PowerLinux™ (RHEL or SLES) operating systems and IBM POWER9® servers, either on IBM AIX or IBM i operating systems. On IBM AIX and PowerLinux, smart cards are required to manage the IBM 4769. See smart card information below for ordering smart cards and smart card readers.
Order a CEX7S for IBM Z
To place an order for the CEX7S feature, contact your IBM Customer Engineer. A minimum of 2 features is required per computer, with a maximum of 60.
Order a 4769-001 for x64
To place an order for a 4769-001, contact your Americas Call Centers, local IBM representative, or your IBM Business Partner. To identify your local IBM representative or IBM Business Partner, contact the Crypto team. You can also use the "Let's talk" button on this page.
Order a 4769 for Power Systems
To order the feature for IBM Power Systems (FC EJ35 or EJ37), see the IBM Power Systems website for information. The coprocessor and its software and firmware are obtained as features of the IBM Power Systems and not from this website.
Order Smart Cards and Readers
On x64, IBM AIX, and PowerLinux, smart cards readers are required to manage and administer the IBM 4769.
- Identiv smart card readersSmart card readers can be ordered from Identiv (SPR332 v2.0 Secure Class 2 PIN Pad Reader (link resides outside of ibm.com), part number 905127-1).Note: IBM cannot guarantee the quality of smart card readers from external sources. Two smart card readers are required because the smart card readers interact during some operations. You may want to consider purchasing one or two additional smart card readers for redundancy.
-
IBM smart cards
IBM smart cards can be ordered from IBM (part number 00RY790, commonly known as blue smart cards). Contact your local IBM representative, your IBM Business Partner, IBM's Directory of worldwide contacts for information about ordering from IBM in your country. In North America, you can also use the IBM Maintenance Parts retail website (link resides outside of ibm.com) to order smart cards.
- Two readers are required because there are operations where smart card readers interact with each other.
- A minimum of two smart cards are needed because you must have a Certificate Authority (CA) smart card and at least one TKE smart card. Please review the Calculate smart card quantity section for details.
Calculate Smart Card Quantity
As stated above, the absolute minimum is two smart cards: one for the CA smart card and one for the TKE smart card.
Important: Although you can manage an HSM with one TKE smart card, this is not recommended. IBM recommends you manage HSMs using dual controls. That requires at least two, and up to five, TKE smart cards in addition to the CA smart card.
| Dual Control for Crypto Module Administration | Number of MK Part Holders | CA Card *Always Required* | Separate Test and Production Crypto Module Environments | Make Backups of Smart Cards | Total Smart Cards Required |
|---|---|---|---|---|---|
| No - 1 (not recommended) | 0 - combine module administrator and MK part holder duties (not recommended) | 1 | No | No | 2 |
| No - 1 (not recommended) | 1 (not recommended) | 1 | No | No | 3 |
| Yes - 2 | 3 | 1 | No | No | 6 |
| Yes - 2 | 2 | 1 | No | No | 5 |
| Yes - 2 | 3 | 1 | No | Yes | 12 |
| Yes - 2 | 2 | 1 | No | Yes | 10 |
| Yes - 2 | 3 | 1 | Yes | No | 12 |
| Yes - 2 | 2 | 1 | Yes | No | 10 |
| Yes - 2 | 3 | 1 | Yes | Yes | 24 |
| Yes - 2 | 2 | 1 | Yes | Yes | 20 |
Contact Us
Contact Cryptocards if you need additional assistance.