Fast Path DEDB area data sets (ADS) encryption
In IMS 15.4, you can encrypt Fast Path DEDB AREA data sets (ADS) by specifying a key label with it. Install APAR PI83756 to enable this feature. Fast Path DEDB area data sets (ADS) uses z/OS data set encryption, which is available in z/OS 2.2 with APAR OA50569 and dependent APARs installed, or in z/OS 2.3 or later.
Restriction
DEDB ADS encryption requires Fast Path 64-bit buffers. This is specified by FPBP64=Y in the FASTPATH section of the DFSDFxxx member in the IMS PROCLIB data set. DEDB ADS encryption is not supported when you are using 31-bit Fast Path buffers.
You must define all data sets that are encrypted by using z/OS data set encryption, including Fast Path DEDB ADS, as SMS-managed extended format data sets. Do not define Fast Path DEDB ADS with the extended addressability attribute. Ensure that the DATACLAS parameter that you use to allocate your ADS does not include the extended addressability attribute.
Migration considerations
- Perform one of the following methods to create encrypted ADS:
- Define the shadow ADS with the same attributes as the non-encrypted ADS and specify key labels with the shadow ADS. Run DEDB ALTER utility.
- Define new ADS as SMS-managed extended format DASD and specify key labels with them. Register
the new ADS to DBRC by using the following command:
INIT.ADS DBD(xxxxxxxx) AREA(yyyyyyyy) ADSN(AREA data set name) UNAVAIL
Run CREATE utility.
- Stop the non-encrypted ADS if necessary.
Coexistence considerations
- All the IMS systems are IMS 15 with APAR PI83756 installed.
- All the IMS systems are using Fast Path 64-bit buffers.
- All the z/OS systems are z/OS 2.2 with OA50569 installed, or z/OS 2.3 and later.
Performance considerations
Additional Fast Path buffers are used when writing to an encrypted area data set. A temporary buffer is obtained at write I/O time to encrypt the data to be written. This buffer is released after the data has been written to the ADS. Each Fast Path buffer includes the buffer itself (64-bit storage) and a 31-bit ECSA control block called a DMHR, which is used to track the buffer. Therefore, encrypting ADS may increase Fast Path 64-bit buffer and ECSA usage. Use the FPBP64M= parameter in the FASTPATH section of the DFSDFxxx member to increase the limit for the amount of 64-bit Fast Path buffers to avoid buffer shortages if necessary. Monitor the 64-bit buffer usage statistics in the IMS 4516 statistics log records when migrating to encrypted ADS.
Documentation changes
The following table lists the publications that contain new or changed topics for the New function name enhancement. Publications that are not impacted by this enhancement are not included in the table.
Publication | Links to topics | ||
---|---|---|---|
Release planning | |||
System administration |