Scenario 1: IBM WebSphere Application Server with internal HTTP transport SSL setup

An overview of the cryptographic software and hardware stack for scenario 1

Prerequisite: The following configuration description assumes that the Linux™ cryptographic setup has been configured as described in IBM Linux on System z cryptographic setup for the IBM WebSphere Application Server SSL support.

For scenario 1, the IBM WebSphere Application Server (WAS) software stack must now be configured to exploit the System z cryptographic features. In scenario 1, the WAS internal HTTP transport will drive the SSL connection.

The following setup recommendations apply to IBM Websphere Application Server Version 8.0. Other WAS versions can have a different look for the administration console.

Figure 1. Overview of the cryptographic software and hardware stack for scenario 1

Block diagram showing overview of WAS and hardware stack, from top to bottom, application, shared libraries, Linux kernel, hardware

Figure 1 outlines the cryptographic flow showing the various levels of application interfaces, Linux shared libraries, and device drivers required to access the IBM System z cryptographic features. WAS uses the Java™ IBMPKCS11Impl for interaction with the PKCS#11 API (openCryptoki). openCryptoki then interacts via the ICA token with the libICA interface library to offload cryptographic operations to CP Assist for Cryptographic Function (CPACF) directly and Crypto Express3 (CEX3) using the zcrypt device driver.