linuxonibm - Documentation Index
Table of Contents
Welcome
Linux on IBM Z and LinuxONE
What's new
Administration and configuration
Device Drivers, Features, and Commands
Kernel 6.18
Distribution specific information
What's new
PDF file
Hypervisors
General concepts
How devices are accessed
Device nodes and numbers
Creating device nodes
udev-created nodes
Network interfaces
Interface names
Matching devices
Main setup steps
Devices in sysfs
Device categories and device drivers
Device directories
Device attributes
Setting attributes
New devices
Device views in sysfs
Device driver view
Device category view
Device view
Channel subsystem view
Subchannel attributes
Channel path ID information
Setting logically on or off
Configuring on LPAR
Mapping PCHIDs and CHPIDs
Read FCES status of a CHPID
CCW hotplug events
Device configuration in PR/SM mode
Device configuration in DPM mode
Manage auto-configuration
Display
Modify
Kernel and module parameters
Specifying kernel parameters
Including in a boot configuration
Length limit
zipl configuration-file mode
zipl command-line mode
z/VM: kernel parameter file
When booting in LPAR or as z/VM guest
Adding parameters
Replacing all parameters
Different sources
Examples
Current parameter line
Kernel parameters for rebooting
Specifying module parameters
With modprobe
On the kernel parameter line
Including in a boot configuration
Module information
Booting and shutdown
Console device drivers
Features
What you should know
Terminology
The zipl boot menu
Device and console names
Terminal device nodes
Terminal modes and available terminals
Console access
HMC for LPAR mode
HMC for z/VM guest
virsh for KVM guest
3270 for z/VM guest
3270 for KVM guest
iucvconn for z/VM guest
Building a kernel
Setup
Kernel parameters
z/VM for iucvconn
Line-mode terminal
Full-screen terminal
3270 terminal
Enabling logins
Using inittab
Using Upstart
Enabling user logins with systemd
Preventing respawns
Preventing respawns with inittab
Preventing respawns with Upstart
Preventing respawns with systemd
x3270 emulation
Working with terminals
Applets on the HMC
Access over IUCV
3270 device driver views
CCW device online or offline
Special characters with line-mode
Magic sysrequest
Activating and deactivating
Triggering from procfs
HMC applet emulation
Priority of commands
Case conversion
Escape character
End-of-line character
Enter and Spacebar
3270 in 3215 mode
3215 full buffer handling
zipl - initial program loader
Usage
Base functions
Modes and syntax overview
Boot device
Kernel parameter concatenation
Logical device as boot device
Using a helper script
Using base parameters
Writing a helper script
Preparing a dump device
Multi-volume dump on DASD
Menu configuration
Parameters
zipl configuration file
Default section
IPL configurations
Defining menu configurations
BLS files
zipl environment
Creating variables
Syntax
Modify the zipl environment block
Common variables
Variables for future use
Site awareness
Define sections
Activate site parameters
Site-aware variables
Booting Linux
IPL and booting
Control and medium
Menu configurations
Boot data
Kernel image
Boot loader code
Kernel parameters
Initial RAM disk
Booting Linux in LPAR mode
From DASD
From SCSI
From NVMe
From tape
From HMC media or remote server
HMC Web Services API
Booting Linux in a DPM partition
DPM partition from SCSI
HMC Web Services API
Booting Linux on z/VM
From tape
From DASD
From DASD in secure-boot mode
From SCSI
From the z/VM reader
Booting Linux on KVM
Current IPL parameters
Rebooting alternative source
Attributes for ccw
Attributes for eckd
Attributes for fcp
Attributes for nvme
Attributes for nss
Kernel panic settings
Configuration examples
Secure boot
Site-specific instantiation
Shutdown actions
Shutdown configuration
CP commands as actions
diag288 watchdog
What you should know
Building a kernel
Setup
Timeout action
Kernel parameters
Module parameters
Assuring device node
Watchdog programming interfaces
KASLR support
Building a kernel with KASLR
Kernel parameters
Storage device drivers
DASD
Features
What you should know
The partitioning scheme
Partitions
Compatible disk layout
Volume label
VTOC
Linux disk layout
CMS disk layout
Disk layout summary
DASD naming scheme
Creating device nodes
udev-created nodes
Access by udev-created nodes
Building a kernel
Setup
Kernel parameters
Module parameters
Device node
Working with DASDs
Preparing ECKD
Preparing FBA
Accessing by force
DIAG access method
Extended error reporting
Setting online or offline
Dynamic attach and detach
Logging
Immediate failure of I/O requests
Timeout for I/O requests
Statistics in debugfs
Gathering and reading examples
Interpreting data rows
PAV and HPF
Full ECKD tracks
Lost reservations
Reservation state reset
Set defective paths offline
Query HPF
Check volume access
ESE DASD
Format
Information
Query FCES
PPRC
Autoquiesce
Requeue
Timeouts
DASD information
SCSI-over-Fibre Channel
Features
What you should know
sysfs structures
SCSI disk device nodes
udev-created nodes
Creating device nodes
Partitioning a SCSI device
zfcp HBA API
NPIV for FCP channels
Building a kernel
Setup
Kernel parameters
Module parameters
Installing the library
Working with FCP devices
Setting online or offline
Displaying information
Recovering failed devices
Diagnostic data
Use of NPIV
I/O subchannel status
Working with target ports
Scanning for ports
Control scanning
Displaying information
Recovering failed ports
Removing ports
Working with SCSI devices
Configuring devices
Automatically attached
Manually configured FCP LUNs
Mapping sysfs representations
Displaying information
Major and minor numbers
Setting the queue depth
Recovering failed devices
Updating device information
Setting the command timeout
Controlling the device state
Removing devices
Automatically attached
Manually configured
End-to-end configurations
End-to-end data consistency
Fibre Channel Endpoint Security
Finding available LUNs
zfcp HBA API
Functions provided
Tools
Environment variables
Storage-class memory
What you should know
Device nodes
Building a kernel
Setup
Working with SCM increments
Display EADM subchannels
List SCM increments
Combine with LVM
NVMe
Channel-attached tape
Features
What you should know
Modes and logical devices
Naming scheme
Creating device nodes
udev-created nodes
Accessing by bus ID
The mt command
Building a kernel
Loading the device driver
Working with tapes
Setting online or offline
Tape information
Compression
Networking
Network Express
Hybrid mode
Configuring FIDPARM to support promiscuous mode on a VF
Direct mode
qeth: OSA-Express and HiperSockets
Device driver functions
What you should know
Layer 2 and layer 3
qeth group devices
Group device setup
Interface names
Support for IPv6
MAC headers in layer 2
MAC headers in layer 3
Outgoing frames
Incoming frames
IP addresses
ARP
Promiscuous mode
Building a kernel
Setup
Loading modules
Switching disciplines
Removing modules
Working with devices
Create group device
Remove group device
Setting layer2
Priority queueing
Inbound buffers
Maximum frame size
Relative port number
Network adapter type
Setting online or offline
Interface name of group
Bus ID of interface
Activating an interface
Confirming that an IP address has been set under layer 3
Duplicate IP addresses
Deactivating an interface
Recovering a device
Checksum offload
Turning inbound checksum calculations on and off
Turning outbound checksum calculations on and off
Enabling and disabling TCP segmentation offload
Isolating connections
QETH statistics
Hardware trace
Working in layer 3
Linux as a router
Taking over IP addresses
Stage 1: Enabling a qeth group device for IP takeover
Stage 2: Activating and deactivating IP addresses for takeover
IPv4 example
IPv6 example
Stage 3: Issuing a command to take over the address
Configuring for proxy ARP
Configuring VIPA
HiperSockets AF_IUCV addressing
Working in layer 2
Configure a Linux bridge
Packet handling
Configure a bridge role
Using HSCI
Create interface
Configuring MTU
Base for MacVTap or OpenVSwitch
VIPA scenario
Setup
Adapter outage
Example
VLAN scenario
Introduction
Configuring VLANs
Example: two VLANs
HiperSockets Network Concentrator
Examples
DHCP with IPv4
DHCP options
Linux as LAN sniffer
HiperSockets NTA
Setting up a z/VM guest LAN sniffer
OSA-Express SNMP subagent
What you should know
Setup
OSA-Express MIB
Access control (snmp.conf)
Working with osasnmpd
Starting osasnmpd
Checking the log file
Issuing queries
Stopping osasnmpd
CTCM device driver
Features
What you should know
CTCM group devices
Interface names
Network connections
Building a kernel
Setup
Working with CTCM devices
Create a group device
Remove a group device
Channel type
Set the protocol
Online or offline
Maximum buffer size
Activate or deactivate interface
Recover lost connection
Scenarios
Peer in different LPAR
z/VM guests on same system
NETIUCV device driver
What you should know about IUCV
Building a kernel with the NETIUCV device driver
Setting up the NETIUCV device driver
Working with IUCV devices
Creating an IUCV device
Changing the peer
Setting the maximum buffer size
Activating an interface
Deactivating and removing an interface
Scenario: Setting up an IUCV connection to a TCP/IP service machine
Setting up the service machine
Setting up Linux instance LNX1
AF_IUCV address family support
Features
Building a kernel
Setup
HiperSockets devices
z/VM guest virtual machine
Loading the modules
Addressing sockets
SMC protocol support
Tools for SMC
Building a kernel
Setup
PNET ID
Statistics
RoCE
Interface names
Building a kernel
Work with the support
Enabling debugging
ISM device driver
Building a kernel
Load the module
List devices
System resources
Channel subsystem
Channel subsystem rescan
Channel path measurement
Managing CPUs
Simultaneous multithreading
CPU capability change
Changing the state
Setting online or offline
CPU topology
Override
CPU polarization
Vertical polarization
Memory hotplug
What you should know
Representation in sysfs
Memory state and reboot
Zones
Building a kernel
Setup
Memory management
Finding the block size
Listing available blocks
Adding memory
Removing memory
Device configuration
Select devices
Enable and disable
View configuration
Change settings
Import or export data
Configure root device
Huge-page support
Building a kernel
Setup huge-page suppor
Working with huge pages
S/390 hypervisor file system
Building a kernel
Directory structure
LPAR
z/VM
Setup
Working with hypfs
Defining permissions
Updating information
CHSC subchannel device driver
Building a kernel
Setup
Assuring device node
Programming interfaces
CLP device driver
Building a kernel
Assuring device node
Programming interfaces
Clock synchronization
Setup
Enabling and disabling
Identifying the IBM Z hardware
HMC media
Building a kernel
Setup
Kernel parameters
Module parameters
Working with media
Assigning to LPAR
Listing files
Mounting
Integrated zEDC data compression
Features
Compression levels
Building a kernel
Confirming acceleration
Overrides
Applications
Kernel
btrfs
GenWQE data compression
Features
What you should know
Accelerated zlib
Device nodes
Virtual accelerators
Compression and speed
Building a kernel
Setup
Examples
Activating for an application
genwqe_gzip
tar
IBM Java
Exploring the setup
Listing accelerators
Device driver setup
Confirming hardware connection
API
PCI Express support
Building a kernel
Setup
Hotplug PCIe devices
Recovering a PCIe device
Report defective devices
PCIe information
Statistics of a PCIe device
z/VM virtual server integration
z/VM concepts
Performance monitoring
Monitoring on z/VM
Monitoring on Linux
Further information
Cooperative memory management
Guest relocation
Writing kernel APPLDATA records
Building a kernel
Setup
Generating records
Enabling the support
Activating data-gathering modules
Setting the sampling interval
Record layout
Programming interfaces
Writing z/VM monitor records
Building a kernel
Setup
Kernel parameters
Module parameters
Setup on z/VM
Working with the writer
Writing and stopping writing
Using monwrite_hdr
Reading z/VM monitor records
What you should know
Building a kernel
Setup
z/VM user directory
Assuring DCSS addressability
Monitor DCSS name
Kernel parameter
Module parameter
Assuring device node
Working with the reader
Opening and closing the device
Reading records
z/VM recording device driver
Features
What you should know
z/VM recording device nodes
Creating device nodes
About records
Building a kernel
Setup
Working with recording devices
Controlling record collection
Purging existing records
Querying the recording status
Opening and closing devices
Scenario: *ACCOUNT service
z/VM unit record device driver
What you should know
Building a kernel
Working with devices
uevent
z/VM DCSS device driver
What you should know
Building a kernel
Setup
Kernel parameters
Module parameters
Avoiding storage overlaps
Working with DCSS devices
Adding a device
Listing DCSSs of a device
Finding the minor number
Setting the access mode
Saving updates
Saving with optional properties
Removing a device
Scenario: Changing contents
z/VM CP interface device driver
What you should know
Building a kernel
Contiguous memory
Using the device node
z/VM SMSG uevent support
Building a kernel
Setup
Kernel parameters
Module parameters
Working with messages
Sending messages
Accessing messages
Writing udev rules
Example udev rule
Cooperative memory management
Building a kernel
Setup
Kernel parameters
Loading the module
Working with CMM
Size of the static pool
Size of the timed pool
KVM virtual server integration
KVM on IBM Z
Versus LPAR and z/VM
Versus distributed systems
Live guest migration
IBM Secure Execution
The virtual CSS
Listing devices
Device types
Listing paths
virtio CCW
Building a kernel
Setting devices offline or online
Block devices
Naming scheme
Mapping to CCW devices
Partitioning
Network devices
Interface names
Mapping to CCW devices
Configuring and activating an interface
SCSI-attached tape devices
SCSI-attached CD/DVD
File system
Set up KVM host
Building a kernel
Setup
VFIO
VFIO
Building a kernel
Host setup
PCI
DASD
Crypto
Security
Cryptographic device driver
Features
Supported adapters
Supported facilities
Prerequisites
What you should know
Functions provided
Adapter discovery
Request processing
Adapter virtualization
AP queue status
Building a kernel
Setup
Kernel parameters
Device node
Customized crypto nodes
AP bus information
Working with devices
Displaying information
Master key states and verification patterns
LPAR configuration
Online or offline
AP interrupts
Set the polling thread
Set the polling interval
Add and remove adapters
Freeing AP queues
External API
uevents
PRNG
Building a kernel
Setup
Kernel parameters
Module parameters
Device node
Device for non-root users
Work with PRNG
Read random numbers
PRNG information
Set the reseed limit
Reseed the PRNG
TRNG
Building a kernel
Setup
Work with TRNG
Read random numbers
TRNG information
Protected key
Building a kernel
Loading the modules
Generate volatile protected keys
Generate secure keys
Swap disks
Programming interfaces
Hardware-accelerated cryptography
Dependencies
Building a kernel
Modules
Confirm
FIPS mode
Building a kernel
Start in FIPS mode
Instruction execution protection
Controlling stack execution protection
Performance
Channel data collection
Setup
Working with the facility
Collecting data
Reading data
CPU-measurement facilities
Building a kernel
Preparation
Authorizing an LPAR
Setting buffer limits
Obtaining details
Using perf
Setup
Reading counters
Collecting sample data
Using the API
PAI
Building a kernel
Cryptographic counters
Analytic counters
Counting mode
Diagnostics and troubleshooting
I/O subchannel status
Obtaining QDIO performance statistics
Control program identification
Specify system name
CPI sysfs interface
System level
System information
Hardware and hypervisor
Retrieving STHYI data
SIE capability
Avoiding common pitfalls
25 GbE RoCE to CISCO
Channel path status
LPAR channel path usage
Ignore I/O devices
Using cio_ignore
z/VM guest: Excessive swapping
Booting stops
LPAR auto-configuration persists
Dump-on-panic
Diagnose codes
Creating a dump
Reference
Commands for Linux on IBM Z
Generic options
chccwdev
chchp
chcpumf
chpstat
chreipl
chshut
chzcrypt
chzdev
cio_ignore
cmsfs-fuse
cpacfinfo
cpacfstats
cpuplugd
Service utility syntax
command-line syntax
Configuration file
For CPU control
For memory control
Predefined keywords
For CPU hotplug rules
For memory hotplug rules
Historical data
Complex rules
Sample configuration file
dasdfmt
dasdstat
dasdview
fdasd
fdasd menu
Menu example
Options example
hmcdrvfs
hsci
hyptop
Navigating
Selecting data
Sorting data
Filtering data
Fields and units
LPAR fields
z/VM fields
Units
CPU types
Examples
Scenario
lschp
lscpumf
lscss
lsdasd
lshmc
lshwc
lsluns
Discover LUNs
Show encryption state
lspai
lsqeth
lsreipl
lsscm
lsshut
lstape
SCSI data fields
lsstp
lszcrypt
lszdev
lszfcp
mon_fsstatd
Systemd syntax
Command-line syntax
Process the data
Read the data
mon_procd
Systemd syntax
Command-line syntax
Process the data
Read the data
osasnmpd
pai
qetharp
qethconf
qethqoat
scsi_logging_level
smc_chk
smc_pnet
smc_rnics
smc_run
smcd
smcr
smcss
tunedasd
vmcp
vmur
Examples
Guest memory dump
Using FTP
Read console transcript
z/VM reader as IPL device
Send files
Send files to z/VSE
zcryptctl
zcryptstats
zdsfs
zipl-editenv
znetconf
zmemtopo
zpcictl
zpwr
Kernel parameters
cio_ignore
Manage exclusions
cmma
maxcpus
noinitrd
nosmt
novx
possible_cpus
ramdisk_size
rd.zdev=no-auto
ro
root
smt
vdso
vmhalt
vmpanic
vmpoff
vmreboot
Diagnose codes
Kernel configuration options
Option dependencies
Architecture-specific
Device driver-related
How to use FC-attached SCSI devices
PDF file
Introduction
SAN and FCP
The zfcp device driver
N_Port ID virtualization
Configure FCP devices
Step 1: IODF configuration
Step 2: Define zones
Step 3: LUN masking
Step 4: Attach a device
Step 5: Configure zfcp
Port scanning
Trigger LUN scan
Persistent device naming
Using udev and zfcp
SCSI device naming
Use multipathing
Implement multipathing
Configure multipathing
Example: TotalStorage DS8000
Example: TotalStorage DS6000
Example: LVM2
Boot with SCSI IPL
What you should know about SCSI IPL
Hardware requirements
SAN addressing
SCSI IPL parameters
Disk preparation
SCSI dump
Example: IODF definition
Example: SCSI IPL of an LPAR
Example: SCSI IPL of a z/VM guest virtual machine
Further reading
Use SCSI tape
SCSI logging
Sysfs statistics
Access the statistics
Interpret the statistics
I/O tracing using blktrace
Capture and analyze I/O data
Capture on a remote system
Parse data
Analyze data
Data for I/O requests
Collect performance data
What you should know
Building a kernel
Prepare ziomon
Work with the monitor
Start the monitor
Stop the monitor
Work with monitoring results
Create performance reports
ziorep_config
Example: Adapter report
Example: SCSI device report
Example: Mapper report
ziorep_utilization
ziorep_utilization examples
ziorep_traffic
Selecting devices
Aggregating data
Example: Summary (default) report
Example: Detailed report
Investigate the SAN fabric
zfcp_ping
zfcp_show
Hints and tips
Setting up TotalStorage DS8000 and DS6000 for FCP
Troubleshooting NPIV
How to Set up a Terminal Server Environment on z/VM
PDF file
Introduction
The environment
iucvtty instances
HVC terminal devices
The iucvconn_on_login script
Respawn prevention
Requirements
Terminal server
Target systems
Security
z/VM IUCV permissions
General for target system
Specific for terminal server
General for terminal server
Terminal server
Access
ts-shell
iucvconn_on_login
Auditing
Logging
Target system
Summary
Setting up a terminal server
z/VM guest virtual machine
s390-tools package
ts-shell
Making a login shell
Creating a user group
Restricting connections
Creating a user
Granting user authorizations
Configuring session transcripts for ts-shell
Installing scriptreplay
iucvconn_on_login
Setting up
Creating a user
Modifying for session transcripts
Setting up the target systems
z/VM guest virtual machine
iucvtty instances
Installing iucvtty
Enabling user logins
systemd examples
inittab examples
Upstart examples
HVC terminal devices
Specifying the number of devices
Activating hvc0 for kernel messages
Restricting access
Setting an initial z/VM user ID filter
Displaying the current filter
Creating a filter file
Changing the filter with an editor
Replacing the current filter
Revoking access restrictions
Permitting root logins
Enabling user logins
Setting the capabilities
systemd examples
inittab examples
Upstart examples
Working with the terminal server
Terminal access from ts-shell
Terminal access through iucvconn_on_login
Terminal access with iucvconn
HVC terminal devices
Session transcripts
Inspecting the logs
Scenarios
Basic scenario
Terminal server
Target system
Terminal sessions
Extended scenario
Terminal server
Target system
Terminal sessions
Transcripts
iucvconn_on_login
Configuration
Terminal sessions
Reference
chiucvallow
iucvconn
iucvtty
lsiucvallow
ts-shell: connect
ts-shell: list
ts-shell: terminal
ts-shell: version, help, exit, quit
ttyrun
ts-shell: authorization file
User ID files
Known issues
Network Express
Networking with PCI adapters and functions
PDF file
Introduction
Network Express
RoCE Express
About PCI network adapters
Why PCI network adapters
PFs, VFs, and ports
Connections
z/OS connectivity
Capabilities
Limitations
Tools
Models and environments
Hardware
Hypervisors
Distributions
Identifiers
PCI function
Interface names
States
Manage PCI functions
Make available
KVM configure
z/VM attach
List
Set online in Linux
Install Linux
Set MTU
Use SE or HMC to configure
Display RDMA information
Use SMC-R
HSCI connections
Troubleshooting
Best practices
High availability
Performance tuning
PNET IDs
Migration
SMC-R scenario
Set up PCIe RoCE Express network
RoCE install videos
High availability
Linux Channel Bonding Best Practices and Recommendations
About this publication
Notational conventions
Overview
The Linux channel bonding concept
Linux on IBM Z with channel bonding
Channel bonding options and recommendations
Bonding modes
Active-backup mode
Option fail_over_mac
Option primary/primary_reselect
802.3ad mode
Option lacp_rate
Option lxmit_hash_policy
Link monitoring
MII monitor
ARP monitor
MII monitor vs. ARP monitor
Setting up channel bonding on different distributions
Preparation
Setting up channel bonding on SLES12
Setting up channel bonding on RHEL 7
Setting up channel bonding on Ubuntu 16.04
Troubleshooting
References
Notices
Trademarks
Terms and conditions
Disaster recovery for Linux on System z
Functional scope
Software prerequisites
Storage (disk subsystem) prerequisites for hardware mirroring
References
Related materials about administration and configuration
KVM Virtual Server Management
KVM Virtual Server Management
September 2025 updates
PDF file
General concepts
Overview
Tasks
Virtualization components
Device virtualization techniques
Virtual SCSI devices
Virtual block devices
DASDs and SCSI disks
NVMe devices
Image files and logical volumes
Storage pools
Virtual SCSI devices
Virtual Ethernet devices
Secure Execution
Device setup
DASDs
SCSI disks
SCSI tape and medium changer devices
NVMe devices
Network devices
Network interface
Direct connection
Bonded interface
Virtual switch
HiperSockets with VNIC
OSA with bridge port
Open vSwitch with Network Express
VFIO pass-through
PCI
DASD
Reassign to VFIO
Create mediated device
AP queues
Free AP queues
Create mediated device
Manage mdev with libvirt
DASD
AP queues
Configuration
Virtual server
Domain configuration-XML
Boot process
virtio block device as IPL device
VFIO DASD as IPL device
ISO image as IPL device
Kernel image file as IPL device
Network IPL device
Example of an initial installation
Virtual CPUs
Number of virtual CPUs
Virtual CPU tuning
CPU model
Virtual memory
Amount
Virtual memory tuning
huge pages
Collection of QEMU core dumps
User space
Persistent Devices
I/O thread polling parameters
Console
Watchdog device
Protected key encryption
Suppressing the balloon device
Devices
Virtio
CCW device specifications
Virtual block devices
DASD, SCSI, or NVMe disk
Example of a DASD configuration
Example of a SCSI disk configuration
NVMe example
Image files as storage devices
Volumes as storage devices
Virtual graphic card
Virtual SCSI devices
Virtual HBAs
SCSI tape or medium changer devices
Example of a multipathed SCSI tape and medium changer device configuration
Virtual SCSI-attached CD/DVD drive
Virtual Ethernet devices
Direct interfaces
Virtual switches
Random number generator
Shared file system
VFIO
Pass-through DASD
Pass-through PCI
Cryptographic adapters
Device configuration-XML
Storage pools
Storage pool and volume configuration-XMLs
Networks
Secure Execution
Prepare virtual server
Bounce buffer by device
Omit conflicting items
Operation
Definition
Define
Modify
Undefine
Life cycle
Start
Terminate
Suspend
Resume
Monitoring
Browse
Display information
Display configuration
Migration
Definition of a virtual server on different hosts using the same configuration-XML
Live migration
Hypervisor release
IBM Z hardware CPU model
Setup
Virtual server resources
Host environments
Phases
Migrate
System resources
Virtual CPUs
Modifying the number of virtual CPUs
CPU weight
Virtual memory
Devices
Attach
Detach
Replace a virtual DVD
Connect to the console
Storage pools
Storage pool management commands
Volume management commands
Networks
Fast path to a guest
Boot from temporary device
Best practices and performance
CPU management
Linux scheduling
CPU weight
Memory management
Storage management
I/O threads
Logical volume management
Performance summary
Diagnostics and troubleshooting
Logging
Log messages
Logging level
Dumping
Automate
Trigger
Test dump configuration
Crash information
Performance metrics
Reference
Life cycle
shut off
running
paused
crashed
in shutdown
Selected libvirt XML elements
Domain configuration-XML
as child of
as child of
,
,
, and
as child of
or
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
as child of
Network configuration-XML
Node-device XML
as root element
Storage pool configuration-XML
Volume configuration-XML
Selected virsh commands
Domain
attach-device
change-media
console
define
destroy
detach-device
domblklist
domblkstat
domcapabilities
domiflist
domifstat
dominfo
domjobabort
domstate
domstats
dump
dumpxml
edit
hypervisor-cpu-baseline
hypervisor-cpu-compare
inject-nmi
iothreadadd
iothreaddel
iothreadinfo
iothreadset
list
managedsave
memtune
migrate
migrate-getspeed
migrate-setmaxdowntime
migrate-setspeed
reboot
resume
schedinfo
shutdown
setvcpus
start
suspend
undefine
vcpucount
Network
net-autostart
net-define
net-destroy
net-dumpxml
net-edit
net-info
net-list
net-name
net-start
net-undefine
net-uuid
Node device
nodedev-create
nodedev-define
nodedev-destroy
nodedev-dumpxml
nodedev-list
nodedev-start
nodedev-undefine
Storage pool
pool-autostart
pool-define
pool-delete
pool-destroy
pool-dumpxml
pool-edit
pool-info
pool-list
pool-name
pool-refresh
pool-start
pool-undefine
pool-uuid
Volume
vol-create
vol-delete
vol-dumpxml
vol-info
vol-key
vol-list
vol-name
vol-path
vol-pool
Selected QEMU commands
QEMU monitor commands
QEMU image command
Hypervisor information for the virtual server user
More information
Related materials about virtualization
Secure execution
What's new
PDF file
Introduction
Benefits
Why attestation
Crypto Express adapters on secure guests
Reboot and shutdown time
Components
Secure a workload
Prerequisites and restrictions
Guest memory
Required software
Required hardware
Workload owner tasks
Encrypting the data volumes
Prepare boot image
Test
Secure the guest
Submit a secret
Association secrets
Prevent misuse
Random secret
CCK-based secret
Bind the request to an instance
Prove the origin
Retrievable secrets
Concepts of retrievable secrets
Submit retrievable secret
Extract header
Clean the guest disk
Communicate setup
Prevent guest dumps
Attesting
Crypto Express adapters
Accelerator mode
Bind using chzcrypt
Bind using pvapconfig
EP11 mode
Secure usage
Bind and associate using chzcrypt
Bind and associate using pvapconfig
Random secret
Given secret
Cloud provider tasks
Find machine serial
Key bundles
Enable the KVM host
Start the virtual server
Troubleshooting
Guests fail to start
Disk attach causes guest crash
Example: Adding a disk to a guest running in secure execution mode
Virsh start fails
Host key document verification fails
Control program identification
Generic SEL guests
Commands
pvimg
pvapconfig
pvattest
pvextract-hdr
pvsecret
Boot configurations
Obtain a host key document
Verify host key document
External programming interfaces
Terminology
All versions
KVM Virtual Server Management
Introducing IBM Secure Execution for Linux
Security
Security concepts
Prime security with Linux on LinuxONE
PDF file
Prime security with Linux
Firmware
Virtualization
Confidential computing
Hardware security modules (HSMs)
Pervasive Encryption and protected key cryptography
Random numbers
Robust memory
Post quantum cryptography
Conclusion
References
Security for Linux on System z
IBM Secure Execution for Linux
Important! Downloading host key documents
White paper: Crypto Express Support for IBM® Secure Execution for Linux
Secure execution
Video explainers
All versions
Secure boot for Linux on IBM Z and IBM LinuxONE
PDF file
Introduction
Requirements
Restrictions
Using
Determining support
Preparing devices
Red Hat Enterprise Linux and Ubuntu
SUSE Linux Enterprise Server
Starting boot
LPAR
z/VM
Verifying secure boot
Certificates
LPAR certificates
HMC steps
DPM mode HMC steps
Keyrings
Enabling third-party modules
Obtaining certificates
Firmware certificates
Using your own keys
Creating private keys
Creating a self-signed certificate
Required signatures
Adding a signature
Verifying a signature
Extracting a signature
Removing a signature
Manually verify a signature
Troubleshooting
Ensuring boot media
Reinstalling boot files
Problems and solutions
More information
Conventions
Authority
Terminology
Mountpoints
Highlighting
How to set an AES master key
Pervasive encryption
Pervasive Encryption for Data Volumes
January 2026
PDF of Disk Encryption using Protected Keys
Summary of changes
Distribution hints
Protected and secure volume encryption
Infrastructure concepts
Terminology
Setting up the infrastructure
Prerequisites
Planning
Device considerations
Crypto adapter considerations
Secure key considerations
Cipher mode considerations
Loading required modules and components
Sample system
Working with encrypted volumes
Creating a volume for pervasive encryption
Opening an encrypted volume
Automatically opening encrypted volumes
Opening and mounting an encrypted volume at user login
Encrypting a volume with a secure key
Migrating to an LVM physical volume
Migrating to a new encrypted disk
Re-encrypting volume from CK to SK
Re-encrypting from CK to SK onto new volume
Re-encrypting a LUKS volume with a secure key
Convert a LUKS2 volume to retrievable PAES keys
Managing keys
Managing SK repository
Location of the secure key repository location
Generating AES secure keys
Validating secure AES keys
Re-enciphering AES secure keys
Importing AES secure keys
Exporting AES secure keys
Listing AES secure keys
Removing AES secure keys from the secure key repository
Changing AES secure keys in the secure key repository
Renaming AES secure keys
Copying AES secure keys
Generating crypttab entries
Generating cryptsetup commands
Managing secure LUKS2 volume keys
Validate LUKS2 volume key
Re-encipher LUKS2 volume key
Set verification pattern of LUKS2 volume key
Set new LUKS2 volume key
Validating a secure key
Validating secure key from secure key repository
Validating secure key from a LUKS2 header
Validating secure key from a file
Changing MKs and re-enciphering SKs
Re-enciphering SK from a repository
Re-enciphering LUKS2 volume keys
Re-enciphering SK from a file
Sharing MKs across cryptographic coprocessors
Replacing a cryptographic coprocessor
Replacing with the same master key
Replacing with different MK
Problem resolution and recovery
Verifying your configuration
Valid physical block size combinations of LVM physical volumes
Troubleshooting problems
Recovering SK encrypted volumes
Recovering encrypted volumes from invalid secure key
Recovering with SK from repository
Encrypting volumes without LUKS
Volume encryption with plain mode
Encrypting an unencrypted volume using plain mode
MK change using plain mode
Unlocking volume in plain mode
Automatically opening in plain mode
Opening at user login in plain mode
Encrypting swap disks with protected keys
Setting up encrypted swap disk
zkey command
zkey pvsecret
zkey-cryptsetup command
All versions
Enterprise Key Management
November 2022 edition
What's New in the 2022 edition
PDF file
Introduction
Using the EKMF plug-in
EKMF Web introduction
Installing EKMF Web
Parts
EKMF Web prerequisites
Set up templates
Create encryption key templates
Create identity templates
Register templates
Set up zkey
Connect
Configure an EKMF Web plug-in
Using zkey with EKMF Web
Generating keys
Change key properties
List keys
Rename a key
Refreshing a key
Reuse keys
Recover a repository
Using the KMIP plug-in
KMIP introduction
Configuring KMIP
KMIP plug-in profiles
Using zkey with KMIP
Generating keys with KMIP
Change key properties
List keys for KMIP
Rename a key
Refresh a key on KMIP
Import a key
Master key change
zkey kms
zkey kms configure
zkey kms configure for the EKMF Web plug-in
zkey kms configure for the KMIP plug-in
zkey generate
zkey kms import
zkey kms list
zkey kms reencipher
zkey kms refresh
zkey remove
Glossary
All versions
Video explainers
Cryptographic hardware support
Cryptographic device drivers
Managing Crypto Express adapters with a TKE
TKE and Crypto Express adapter
TKE setup for EP11
Additional EP11 documentation
TKE setup for CCA
openCryptoki: Open Source PKCS #11
openCryptoki Version 3.25
PDF file
About this document
Summary of changes
Edition SC34-7730-03: Updates for openCryptoki versions 3.23 - 3.25
Edition SC34-7730-02: Updates for openCryptoki versions 3.18 - 3.22
Edition SC34-7730-01: Updates for openCryptoki version 3.17
openCryptoki features
PKCS #11 and openCryptoki
What is PKCS #11?
What is openCryptoki?
Architecture and components of openCryptoki
Preparing openCryptoki
Fastpath to openCryptoki
Installing openCryptoki
openCryptoki configuration file
Token access control
Cryptographic policies
Strength configuration file
Policy configuration file
Processing configuration files
Environment variables
openCryptoki tools
pkcsconf
p11sak
pkcstok_migrate
pkcsstats
pkcshsm_mk_change
pkcstok_admin
p11kmip
Token specifications
Common token information
Adding tokens to openCryptoki
Token user access
Recognize tokens
ECC header file
OID file for QSA
Protected keys
AES XTS support
Baseline Provider support
Dual-function cryptographic functions
PKCS #11 3.0 - 3.2 features
CCA token
CCA key types
CCA token configuration file
CCA token mechanisms
Wrapping CCA keys
ECDH to derive AES keys
CCA token ECC curves
Usage notes for CCA library functions
pkcscca: migrate master key
ICA token
ICA token mechanisms
Usage notes for the ICA library functions
ICA token ECC curves
EP11 token
EP11 token configuration file
EP11 token mechanisms
EP11 token ECC curves
pkcsep11_migrate
Session modes
pkcsep11_session
Usage notes for the EP11 host library functions
Restriction to extended evaluations
Soft token
Soft token mechanisms
Token directories
ICSF token
pkcsicsf
IBM-specific mechanisms and features for openCryptoki
IBM post quantum mechanisms
IBM-specific mechanisms for openCryptoki
IBM-specific key derivation functions
IBM-specific mask generation functions
IBM-specific attributes
Re-encrypt data with a mechanism
Programming basics and user scenarios
Programming with openCryptoki
Create and modify objects
openCryptoki attributes
Structure of an openCryptoki application
openCryptoki sample program
Code samples (C)
Trouble shooting
Configuring a remote PKCS #11 service
Server side setup
Client side setup
p11-kit
All versions
OpenSSL: Support for IBM Z and IBM LinuxONE
OpenSSL support for Linux on IBM Z and IBM LinuxONE
PDF file: OpenSSL support for Linux on IBM Z and IBM LinuxONE
About this document
Summary of changes
Edition SC34-7732-01 - 2025
OpenSSL introduction
Quick decision
OpenSSL on IBM Z
IBMCA in OpenSSL
Decide the flavor of IBMCA
Using IBMCA provider
IBMCA provider features
IBMCA provider configuring
Usage notes
Using IBMCA engine
IBMCA engine features
IBMCA engine configuring
IBMCA engine restrictions
Concepts of IBM crypto HW
CPACF
Crypto Express features
Installing IBMCA
IBMCA installing from distro
IBMCA installing from source
Build-time configuration
Obtaining statistics
Monitoring CPACF activity
lszcrypt statistics
icastats statistics
Troubleshooting and debugging
IBMCA engine trouble shooting
IBMCA provider trouble shooting
Use cases with IBMCA
IBMCA provider use case (Apache)
IBMCA engine use case (OpenSSH)
Use cases with PKCS#11
PKCS#11 provider use case
OpenSSL 3.0: PKCS#11 general provider
Apache HTTP Server configuration for PKCS#11 provider
PKCS#11 libp11 engine use case
All versions
Secure Key Solution with the Common Cryptographic Architecture Application Programmer's Guide
CCA 8.4
PDF file
About this document
Revision history
Edition September 2025, CCA Support Program Releases 8.4 and 7.6
Internal only: CCA Support Program Release 8.3
Edition August 2024, CCA Support Program Releases 8.2 and 7.5
Edition November 2023, CCA Support Program Release 8.1
Who should use this document
Distribution-specific information
Terminology
Hardware requirements
How to use this document
Where to find more information
Cryptography publications
IBM CCA programming
Programming with CCA
CCA verbs
CCA functional overview
How application programs obtain service
Overlapped processing and load balancing
Domain selection capabilities
Domain query capabilities
Multi-coprocessor selection capabilities
CPACF support
Environment variables
CSU_HCPUACLR
CSU_HCPUAPRT
Access control points
CPACF operation (protected key)
Using keys with CPACF, protected key
Using keys with CPACF, clear key or no key
CCA library CPACF preparation at startup
Interaction between the default card and use of protected key CPACF
AUTOSELECT and protected key CPACF
Security API fundamentals
Verbs, variables, and parameters
Common parameters
Parameters common to all verbs
The rule_array and other keyword parameters
Key tokens, key labels, and key identifiers
Compile and link CCA programs
Using the Master Key Process (CSNBMKP) verb
Building C applications using the CCA libraries
Using the CCA JNI
Calling the CCA JNI
Entry points and data types used in the JNI
JNI sample modules and sample code
Preparing your Java environment
Building Java applications using the CCA JNI
Building the Java byte code
Running the Java byte code
PCI-HSM 2016 compliance mode
Compliance modes
HSM modes
Compliance warnings
AES, DES, and HMAC cryptography and verbs
AES, DES, and HMAC key functions
Key separation
Master key variant for fixed-length tokens
Transport key variant for fixed-length tokens
Key forms
Key token
Compliant-tagged key tokens
Key wrapping
AES key
DES key
AESKW method
Key strength and wrapping
Key wrapping ACPs
Control vector
Types of keys
DES key restrictions
Triple-length TDES keys
Verbs for managing AES and DES key storage files
Verbs for managing the PKA key storage file and PKA keys in the cryptographic engine
Key agreement models
Hybrid PQC key exchange scheme
Improved remote key distribution
Remote key loading
Verbs supporting Secure Sockets Layer (SSL)
Data integrity and message authentication
Processing message authentication
Hashing functions
Processing PINs
Secure messaging
Trusted Key Entry support
CCA verbs sequences
CCA node and master key management
CCA nodes and resource control verbs summary
AES, DES, and HMAC verbs summary
PKA cryptography and PKA verbs
PKA key algorithms
PKA master keys
PKA verbs
Digital signatures
PKA key management
Key identifier for PKA key token
Key label
PKA key token
X.509 certificates
PKA verbs summary
TR-31 symmetric-key management
Understanding master keys
Symmetric and asymmetric master keys
Establishing master keys
CCA verbs
CCA nodes and resource control
Access Control Maintenance (CSUAACM)
Format
Parameters
Required commands
Usage notes
JNI version
Access Control Tracking (CSUAACT)
Format
Parameters
Interval tracking data structure
Required commands
JNI version
Cryptographic Facility Query (CSUACFQ)
Determining the CEX*C card
Format
Parameters
Data returned for CSUACFQ keywords
DOM-CONT
DOM-NUMS
DOM-USAG
GETCOMPD
GET-UDX
NUM-DECT
SIZEWPIN
STATDECT
STATICSA
STATICSB
STATICSC
STATICSE
STATICSX
STATKPR
STATKPRL
STATOAH2
STATOAHL
STATVKPL
STATVKPR
STATTKPL
STATTKPR
STATWPIN
Restrictions
Usage notes
JNI version
Cryptographic Facility Version (CSUACFV)
Format
Parameters
JNI version
Cryptographic Resource Allocate (CSUACRA)
Format
Parameters
Restrictions
Usage notes
JNI version
Cryptographic Resource Deallocate (CSUACRD)
Format
Parameters
Restrictions
Usage notes
JNI version
Key Storage Initialization (CSNBKSI)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Log Query (CSUALGQ)
Format
Parameters
Required commands
JNI version
Master Key Process (CSNBMKP)
Format
Parameters
Restrictions
Required commands
Usage notes
Questionable DES keys
JNI version
Random Number Tests (CSUARNT)
Format
Parameters
Usage notes
JNI version
AES, DES, and HMAC cryptographic keys
Clear Key Import (CSNBCKI)
Format
Parameters
Required commands
JNI version
Control Vector Generate (CSNBCVG)
Format
Parameters
Restrictions
Usage notes
JNI version
Control Vector Translate (CSNBCVT)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Cryptographic Variable Encipher (CSNBCVE)
Format
Parameters
Restrictions
Required commands
JNI version
Data Key Export (CSNBDKX)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Data Key Import (CSNBDKM)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Diversified Key Generate (CSNBDKG)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Diversified Key Generate2 (CSNBDKG2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Diversify Directed Key (CSNBDDK)
Format
Parameters
Required commands
JNI version
EC Diffie-Hellman (CSNDEDH)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Export (CSNBKEX)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Generate (CSNBKGN)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Generate2 (CSNBKGN2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Import (CSNBKIM)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Part Import (CSNBKPI)
Format
Parameters
Restrictions
Required commands
JNI version
Key Part Import2 (CSNBKPI2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Test (CSNBKYT)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Test2 (CSNBKYT2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Test Extended (CSNBKYTX)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Key Token Build (CSNBKTB)
Format
Parameters
Restrictions
Usage notes
JNI version
Key Token Build2 (CSNBKTB2)
Format
Parameters
Keywords reference
Restrictions
Usage notes
JNI version
Key Token Change (CSNBKTC)
Format
Parameters
Restrictions
Required commands
JNI version
Key Token Change2 (CSNBKTC2)
Format
Parameters
Restrictions
Required commands
JNI version
Key Token Parse (CSNBKTP)
Format
Parameters
Restrictions
Usage notes
JNI version
Key Token Parse2 (CSNBKTP2)
Format
Parameters
Restrictions
Usage notes
JNI version
Key Translate (CSNBKTR)
Format
Parameters
Restrictions
Required commands
JNI version
Key Translate2 (CSNBKTR2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Multiple Clear Key Import (CSNBCKM)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Multi-MAC Scheme (CSNBMMS)
Format
Parameters
Required commands
Usage notes
JNI version
PKA Decrypt (CSNDPKD)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
PKA Encrypt (CSNDPKE)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Prohibit Export (CSNBPEX)
Format
Parameters
Required commands
JNI version
Prohibit Export Extended (CSNBPEXX)
Format
Parameters
Restrictions
Required commands
JNI version
Restrict Key Attribute (CSNBRKA)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Random Number Generate (CSNBRNG)
Format
Parameters
Required commands
JNI version
Random Number Generate Long (CSNBRNGL)
Format
Parameters
Restrictions
Required commands
JNI version
Remote Key Export (CSNDRKX)
Generating and exporting DES keys
Format
Parameters
Restrictions
Required commands
JNI version
Symmetric Key Export (CSNDSYX)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Symmetric Key Export with Data (CSNDSXD)
Format
Parameters
Restrictions
Required commands
JNI version
Symmetric Key Generate (CSNDSYG)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Symmetric Key Import (CSNDSYI)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Symmetric Key Import2 (CSNDSYI2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Trusted Block Create (CSNDTBC)
Format
Parameters
Restrictions
Required commands
JNI version
Unique Key Derive (CSNBUKD)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Protecting data
Modes of operation
Cipher Block Chaining (CBC) mode
Electronic Code Book (ECB) mode
Electronic Code Book (ECB) mode
Processing rules
Triple DES encryption
Decipher (CSNBDEC)
Host CPU acceleration: CPACF
Format
Parameters
Restrictions
Required commands
JNI version
Encipher (CSNBENC)
Host CPU acceleration: CPACF
Format
Parameters
Restrictions
Required commands
JNI version
Symmetric Algorithm Decipher (CSNBSAD)
Format
Parameters
Restrictions
Required commands
JNI version
Symmetric Algorithm Encipher (CSNBSAE)
Format
Parameters
Restrictions
Required commands
JNI version
Cipher Text Translate2 (CSNBCTT2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Data integrity and message authentication
How MACs are used
How hashing functions and MDCs are used
HMAC Generate (CSNBHMG)
Format
Parameters
Restrictions
Required commands
Usage notes
Related information
JNI version
HMAC Verify (CSNBHMV)
Format
Parameters
Restrictions
Required commands
Usage notes
Related information
JNI version
MAC Generate (CSNBMGN)
Host CPU acceleration: CPACF
Format
Parameters
Restrictions
Required commands
JNI version
MAC Generate2 (CSNBMGN2)
Format
Parameters
Restrictions
Required commands
Usage notes
Related information
JNI version
MAC Verify (CSNBMVR)
Host CPU acceleration: CPACF
Format
Parameters
Restrictions
Required commands
Usage notes
Related information
JNI version
MAC Verify2 (CSNBMVR2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
MDC Generate (CSNBMDG)
Format
Parameters
Restrictions
Required commands
JNI version
One-Way Hash (CSNBOWH)
Format
Parameters
Restrictions
Usage notes
JNI version
Key storage mechanisms
Manage key storage
Environment variables for key store files
Environment variables for key-record-list files
Redirect to CMB key storage verbs
Key-label content
Key storage with Linux on IBM Z, in contrast to z/OS on IBM Z
Background information about master key management
SET command
Key storage on z/OS (RTNMK-focused)
Key storage for traditional IBM systems other than IBM Z (RTCMK-focused: Linux, AIX, Windows)
Changing the master key for adapters with same master key
Key storage file ownership
The Linux on IBM Z approach
AES Key Record Create (CSNBAKRC)
Format
Parameters
Restrictions
Related information
JNI version
AES Key Record Delete (CSNBAKRD
Format
Parameters
Restrictions
Related information
JNI version
AES Key Record List (CSNBAKRL)
Format
Parameters
Related information
JNI version
AES Key Record Read (CSNBAKRR)
Format
Parameters
Related information
JNI version
AES Key Record Write (CSNBAKRW)
Format
Parameters
Restrictions
Related information
JNI version
DES Key Record Create (CSNBKRC)
Format
Parameters
Restrictions
Related information
JNI version
DES Key Record Delete (CSNBKRD)
Format
Parameters
Restrictions
Related information
JNI version
DES Key Record List (CSNBKRL)
Format
Parameters
Related information
JNI version
DES Key Record Read (CSNBKRR)
Format
Parameters
Restrictions
Related information
JNI version
DES Key Record Write (CSNBKRW)
Format
Parameters
Restrictions
Related information
JNI version
PKA Key Record Create (CSNDKRC)
Format
Parameters
Related information
JNI version
PKA Key Record Delete (CSNDKRD)
Format
Parameters
Related information
JNI version
PKA Key Record List (CSNDKRL)
Format
Parameters
Related information
JNI version
PKA Key Record Read (CSNDKRR)
Format
Parameters
Related information
JNI version
PKA Key Record Write (CSNDKRW)
Format
Parameters
Related information
JNI version
Combined Key Record Create (CSNBCKRC)
Format
Parameters
Usage notes
Related information
JNI version
Combined Key Record Delete (CSNBCKRD)
Format
Parameters
Related information
JNI version
Combined Key Record List (CSNBCKRL)
Format
Parameters
Usage notes
Related information
JNI version
Combined Key Record Read (CSNBCKRR)
Format
Parameters
Required commands
Related information
JNI version
Combined Key Record Write (CSNBCKRW)
Format
Parameters
Required commands
Related information
JNI version
Retained Key Delete (CSNDRKD)
Format
Parameters
Using retained keys
Required commands
Usage notes
Related information
JNI version
Retained Key List (CSNDRKL)
Format
Parameters
Required commands
Usage notes
Related information
JNI version
Financial services
How personal identification numbers (PINs) are used
How Visa card verification values are used
Translating data and PINs in networks
Working with Europay-Mastercard-Visa Smart cards
PIN verbs
Generating a PIN
Encrypting a PIN
Generating a PIN validation value from an encrypted PIN block
Verifying a PIN
Translating a PIN
Generate and verify PIN
Using PINs on different systems
PIN-Encrypting keys
ANSI X9.8 PIN restrictions
ANSI X9.8 PIN - Enforce PIN block restrictions
ANSI X9.8 PIN - Allow modification of PAN
ANSI X9.8 PIN - Allow only ANSI PIN blocks
Use stored decimalization tables only
The PIN profile
Format control
Current key serial number
Decimalization tables
Format preserving encryption
Authentication Parameter Generate (CSNBAPG)
Format
Parameters
Restrictions
Required commands
JNI version
Clear PIN Encrypt (CSNBCPE)
Format
Parameters
Restrictions
Required commands
JNI version
Clear PIN Generate (CSNBPGN)
Format
Parameters
Restrictions
Required commands
Usage notes
Related information
JNI version
Clear PIN Generate Alternate (CSNBCPA)
Format
Parameters
Restrictions
Required commands
JNI version
CVV Generate (CSNBCSG)
Format
Parameters
Restrictions
Required commands
JNI version
CVV Key Combine (CSNBCKC)
Format
Parameters
Restrictions
Required commands
JNI version
CVV Verify (CSNBCSV)
Format
Parameters
Restrictions
Required commands
JNI version
Encrypted PIN Generate (CSNBEPG)
Format
Parameters
Restrictions
Required commands
JNI version
Encrypted PIN Translate (CSNBPTR)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Encrypted PIN Translate2 (CSNBPTR2)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Encrypted PIN Translate Enhanced (CSNBPTRE)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Encrypted PIN Verify (CSNBPVR)
Format
Parameters
Restrictions
Required commands
Related information
JNI version
Encrypted PIN Verify2 (CSNBPVR2)
Format
Parameters
Restrictions
Required commands
JNI version
FPE Decipher (CSNBFPED)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
FPE Encipher (CSNBFPEE)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
FPE Translate (CSNBFPET)
Format
Parameters
Restrictions
Required commands
JNI version
FPE Algorithms Decipher (CSNBFFXD)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
FPE Algorithms Encipher (CSNBFFXE)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
FPE Algorithms Translate (CSNBFFXT)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
PIN Change/Unblock (CSNBPCU)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Recover PIN from Offset (CSNBPFO)
Format
Parameters
Restrictions
Required commands
JNI version
Secure Messaging for Keys (CSNBSKY)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Secure Messaging for PINs (CSNBSPN)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Transaction Validation (CSNBTRV)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
DK PIN methods
Weak PIN table
DK PIN methods
DK Deterministic Generate (CSNBDDPG)
Format
Parameters
Restrictions
Required commands
JNI version
DK Migrate PIN (CSNBDMP)
Format
Parameters
Restrictions
Required commands
JNI version
DK PAN Modify in Transaction (CSNBDPMT)
Format
Parameters
Restrictions
Required commands
JNI version
DK PAN Translate (CSNBDPT)
Format
Parameters
Restrictions
Required commands
JNI version
DK PIN Change (CSNBDPC)
Format
Parameters
Restrictions
Required commands
JNI version
DK PIN Verify (CSNBDPV)
Format
Parameters
Restrictions
Required commands
JNI version
DK PRW Card Number Update (CSNBDPNU)
Format
Parameters
Restrictions
Required commands
JNI version
DK PRW Card Number Update2 (CSNBDCU2)
Format
Parameters
Required commands
JNI version
DK PRW CMAC Generate (CSNBDPCG)
Format
Parameters
Restrictions
Required commands
JNI version
DK Random PIN Generate (CSNBDRPG)
Format
Parameters
Restrictions
Required commands
JNI version
DK Random PIN Generate2 (CSNBDRG2)
Format
Parameters
Required commands
JNI version
DK Regenerate PRW (CSNBDRP)
Format
Parameters
Restrictions
Required commands
JNI version
TR-34 symmetric key management
Protocol
User flows
Setup
BIND
UNBIND
REBIND
2-pass key transport
1-pass key transport
TR-34 Bind-Begin (CSNDT34B)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
TR-34 Bind-Complete (CSNDT34C)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
TR-34 Key Distribution (CSNDT34D)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
TR-34 Key Receive (CSNDT34R)
Format
Parameters
Restrictions
Usage notes
Required commands
JNI version
TR-31 symmetric key management
TR31 Key Create (CSNBT31C)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
TR31 Translate (CSNBT31X)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
TR31 Key Import (CSNBT31I)
Format
Parameters
Restrictions
Required commands
Usage notes
Special notes
Examples
JNI version
TR31 Key Token Parse (CSNBT31P)
Format
Parameters
Usage notes
JNI version
TR31 Optional Data Build (CSNBT31O)
Format
Parameters
Restrictions
Usage notes
JNI version
TR31 Optional Data Read (CSNBT31R)
Format
Parameters
JNI version
Using digital signatures
Digital Signature Generate (CSNDDSG)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
Digital Signature Verify (CSNDDSV)
Format
Parameters
Restrictions
Required commands
Usage notes
Related information
JNI version
Managing PKA cryptographic keys
PKA Key Generate (CSNDPKG)
Format
Parameters
Restrictions
Required commands
JNI version
PKA Key Import (CSNDPKI)
Format
Parameters
Restrictions
Required commands
Usage notes
JNI version
PKA Key Token Build (CSNDPKB)
Format
Parameters
Restrictions
JNI version
PKA Key Token Change (CSNDKTC)
Format
Parameters
Required commands
Usage notes
JNI version
PKA Key Translate (CSNDPKT)
Format
Parameters
Restrictions
Required commands
JNI version
PKA Public Key Extract (CSNDPKX)
Format
Parameters
Usage notes
JNI version
Trusted Block Create (CSNDTBC)
Format
Parameters
Restrictions
Required commands
JNI version
Public Infrastructure Certificate (CSNDPIC)
Format
Parameters
Required commands
JNI version
Public Infrastructure Manage (CSNDPIM)
Format
Parameters
Restrictions
Required commands
JNI version
Utility verbs
Code Conversion (CSNBXEA)
Format
Parameters
Usage notes
JNI version
Reference information
Return and reason codes
Return codes
Reason codes
Reason codes for return code 0
Reason codes for return code 4
Reason codes for return code 8
Reason codes for return code 12
Reason codes for code 16
Key token formats
Master-key verification pattern
Token validation value
Null key tokens
Fixed-length symmetric key tokens
AES internal fixed-length key token
AES internal fixed-length key-token flag byte
DES internal key token
DES external key token
RKX DES key tokens
Variable-length symmetric key tokens
General format of a variable-length symmetric key-token
AES CIPHER
AES MAC
HMAC MAC variable-length symmetric key token
AES EXPORTER and IMPORTER
AES PINPROT, PINCALC, and PINPRW
AES DESUSECV
AES DKYGENKY
AES SECMSG
PKA key tokens
PKA null key token
PKA key token sections
Integrity of PKA private key sections
Number representation in PKA key tokens
PKA public-key certificate section
RSA public key token
RSA private key token
RSA private external key token
RSA private internal key token
RSA private key token, 1024-bit Modulus-Exponent
RSA private key, 1024-bit Modulus-Exponent with OPK
RSA private key token, 8192-bit Modulus-Exponent
RSA private key, 8192-bit Modulus-Exponent format with AES encrypted OPK section
RSA private key, 8192-bit Chinese Remainder Theorem format with AES encrypted OPK section
RSA private key, 2048-bit Chinese Remainder Theorem
RSA private key, 8192-bit Chinese Remainder Theorem with OPK
RSA private key token, 1024-bit Modulus-Exponent internal format for cryptographic coprocessor feature
RSA variable Modulus-Exponent token
ECC key token
PQC key token
HMAC key token
AESKW key format
TR-31 key header and optional data
TR-31 key block header
TR-31 optional block data
Trusted blocks
Trusted block organization
Trusted block integrity
Number representation in trusted blocks
Trusted block sections
Trusted block section X'11'
Trusted block section X'12'
Trusted block section X'12' subsections
Trusted block section X'13'
Trusted block section X'14'
Trusted block section X'14' subsections
Trusted block section X'15'
Key forms and types used in the Key Generate verb
Generating an operational key
Generating an importable key
Generating an exportable key
Examples of single-length keys in one form only
Examples of OPIM single-length, double-length, and triple-length keys in two forms
Examples of OPEX single-length, double-length, and triple-length keys in two forms
Examples of IMEX single-length and double-length keys in two forms
Examples of EXEX single-length and double-length keys in two forms
Key-record-list
Control vectors with the Control Vector Translate verb
Control vector table
Control-vector base bit maps
Key form bits, fff and FFF
Specifying a control-vector-base value
Changing control vectors
Providing the control information for testing the control vectors
Mask array preparation
Key-half processing mode
Null target key-token CV
Example
Key type vectors
PIN formats and algorithms
PIN notation
PIN block formats
ANSI X9.8
ISO Format 1
ISO Format 2
ISO Format 3
ISO Format 4
Visa Format 2
Visa Format 3
4700 Encrypting PINPAD Format
IBM 3624 Format
IBM 3621 Format
ECI Format 2
ECI Format 3
PIN extraction rules
Encrypted PIN Verify verb
Clear PIN Generate Alternate
Encrypted PIN Translate
PIN Change/Unblock
IBM PIN algorithms
3624 PIN generation
German Banking Pool PIN generation
PIN offset generation algorithm
3624 PIN verification
German Banking Pool PIN verification
VISA PIN algorithms
PVV Generation algorithm
PVV Verification algorithm
Interbank PIN Generation algorithm
Cryptographic algorithms and processes
Cryptographic key-verification techniques
Master-key verification
SHA-1 based method
z/OS-based master-key verification method
SHA-256 based master-key verification method
Asymmetric master key MDC-based method
Verification patterns
CCA DES-key verification
Encrypt zeros AES-key verification algorithm
Encrypt zeros DES-key verification algorithm
SHAVP1 algorithm
MDC method
Ciphering methods
General data-encryption processes
Single-DES and Triple-DES encryption algorithms for general data
ANSI X3.106 Cipher Block Chaining (CBC) method
ANSI X9.23 cipher block chaining
Triple-DES algorithms
MAC calculation methods
ANSI X9.9 MAC
ANSI X9.19 Optional Procedure 1 MAC
EMV MAC
ISO 16609 TDES MAC
Keyed-hash MAC (HMAC)
RSA key-pair generation
Multiple de- and encipherment
Single-length key encipherment
Single-length key decipherment
Double-length key encipherment
Double-length key decipherment
Triple-length key encipherment
Triple-length key decipherment
PKA92 key format and encryption process
Formatting hashes and keys in public-key cryptography
ANSI X9.31 hash format
PKCS #1 hash formats
DUKPT calculation
Deriving an ANS X9.24 DUKPT key
Special encryption and decryption
Access control points and verbs
Access control data structures
Role structures
Basic role structure
Access control point list
Default role contents
Examples of the access control data structures
ACP list - data structure sample
Role data structure sample
Using verbs and applications in PCI-HSM 2016
Generating PCI-HSM 2016 compliant keys
Impact of PCI-HSM 2016 on callable verbs
Restrictions on PCI-HSM 2016 compliant keys
Restrictions on PIN block translation operations
Generating warning events
Migrating to PCI-HSM 2016
AES-DUKPT reference
Sample verb call routines
Sample program in C
Sample program in Java
Initial system set-up tips
Installing and loading the cryptographic device driver
Unloading the cryptographic device driver
Confirming your cryptographic devices
Checking the adapter settings
Performance tuning
Running secure key under a z/VM guest
CCA installation instructions
Before you begin
Compatibility considerations
Default installation directory
Download and install the RPM or DEB file
Files in the RPM or DEB
Samples in the RPM or DEB
Groups in the RPM or DEB
Install and configure the RPM
Verify RPM or DEB package
Uninstall the RPM or DEB
TKE catcher for TLS connection
CEX*C feature coexistence
Concurrent installations
CEX8C information
Utilities
Master Key administration
The panel.exe utility
panel.exe default syntax
panel.exe legacy syntax
panel.exe functions
Using panel.exe for key storage initialization
Using panel.exe to migrate keys to CMB key storage
Using panel.exe for key storage re-encipher when changing the master key
panel.exe: show active role and ACPs
panel.exe: control ACP tracking
panel.exe: verify CCA epoch certificates
panel.exe: query the adapter compliance state
Security API command codes
openCryptoki
List of abbreviations
All versions
Exploiting Enterprise PKCS #11 using openCryptoki
EP11 3.0 on openCryptoki 3.15
PDF of Enterprise PKCS #11
Summary of changes
Updates for the EP11 token for openCryptoki versions 3.11 up to 3.15
Updates for the openCryptoki version 3.10 EP11 token type
Introduction
What is PKCS #11?
What is openCryptoki?
What is a Crypto Express EP11 coprocessor?
The EP11 crypto stack
openCryptoki overview
Building the EP11 crypto stack
Preparing the Crypto Express EP11 coprocessor
Purpose of domains
Assigning adapters and domains to LPARs
Enabling a CEX*P adapter for EP11 firmware exploitation
Assigning EP11 adapters as dedicated adapters to z/VM guests
Installing and loading the cryptographic device driver
Installing the host part of the EP11 library
Setting a master key on the Crypto Express EP11 coprocessor
Installing openCryptoki
Configuring openCryptoki for EP11 support
Adjusting the openCryptoki configuration file
Adding EP11 tokens to openCryptoki
Defining an EP11 token-specific configuration file
Setting environment variables
Initializing EP11 tokens
How to recognize an EP11 token instance
Using an EP11 token
Supported mechanisms for the EP11 token
Filtering mechanisms
Importing keys
Quantum safe cryptography
Supported ECC curves
Re-encrypting data with a new key and mechanism
BSICC2017 compliance mode
Controlling access to crypto objects
Restrictions using the EP11 library
Restriction to extended evaluations
Troubleshooting EP11
Checking the device driver status
Checking the EP11 token status
Enabling the logging support while running the EP11 token
Tools and utilities
EP11 information tool: ep11info
EP11 master key migration tool: pkcsep11_migrate
EP11 session tool: pkcsep11_session
pkcstok_migrate tool
Programming examples for openCryptoki
Base procedures
Session and log-in procedures
Object handling procedures
Cryptographic operations
All versions
Video explainers
libzpc - A Protected-Key Cryptographic Library
libzpc 1.5
PDF for libzpc
About this document
Summary of changes
Edition SC34-7731-04: Content for libzpc version 1.5
Edition SC34-7731-03: Content for libzpc versions 1.3 and 1.4
Edition SC34-7731-02: Content for libzpc version 1.2
Concepts
Crypto HW categories
Keys for crypto HW
Preparing libzpc
Building
Testing
Installing
Configuring
Programming with libzpc
Lifecycle
ECC considerations
Retrievable secrets considerations
Error handling
APIs
AES key APIs
AES CBC APIs
AES CCM APIs
AES CMAC APIs
AES ECB APIs
AES GCM APIs
AES XTS APIs
AES Full-XTS key APIs
AES Full-XTS APIs
ECC key APIs
ECDSA APIs
HMAC key APIs
HMAC APIs
Error API
Sample programs
All versions
libica Programmer's Reference
libica 4.4
PDF for libica Programmer's Reference
About this document
Who should read this document
Distribution independence
Summary of changes
Updates for libica version 4.4
Updates for libica version 4.3
Updates for libica versions 4.1 and 4.2
General information
Cryptographic coprocessors
Installing the cryptographic device driver
Accessing libica through openCryptoki
Installing and using libica
Installing from distribution packages
Installing from source package
Using libica
Using libica in FIPS mode
FIPS 140-2 mode
FIPS 140-3 mode
Enabling FIPS mode
libica APIs
General support functions
ica_open_adapter
ica_close_adapter
ica_set_fallback_mode
ica_set_offload_mode
ica_set_stats_mode
Secure hash operations
ica_sha224
ica_sha256
ica_sha384
ica_sha512
ica_sha512_224
ica_sha512_256
ica_sha3_224
ica_sha3_256
ica_sha3_384
ica_sha3_512
ica_shake_128
ica_shake_256
Pseudo random number generation
ica_random_number_generate
ica_drbg_instantiate
ica_drbg_reseed
ica_drbg_generate
ica_drbg_uninstantiate
ica_drbg_health_test
RSA key generation
ica_rsa_key_generate_mod_expo
ica_rsa_key_generate_crt
ica_rsa_crt_key_check
RSA encrypt and decrypt
ica_rsa_mod_expo
ica_rsa_crt
Elliptic curve (ECC) functions
ica_ec_key_new
ica_ec_key_init
ica_ec_key_generate
ica_ec_key_free
ica_ecdh_derive_secret
ica_ec_get_public_key
ica_ec_get_private_key
ica_ecdsa_sign
ica_ecdsa_sign_ex
ica_ecdsa_verify
ica_x25519_ctx_new
ica_x448_ctx_new
ica_ed25519_ctx_new
ica_ed448_ctx_new
ica_x25519_key_set
ica_x448_key_set
ica_ed25519_key_set
ica_ed448_key_set
ica_x25519_key_get
ica_x448_key_get
ica_ed25519_key_get
ica_ed448_key_get
ica_x25519_key_gen
ica_x448_key_gen
ica_ed25519_key_gen
ica_ed448_key_gen
ica_x25519_key_derive
ica_x448_key_derive
ica_ed25519_sign
ica_ed448_sign
ica_ed25519_verify
ica_ed448_verify
ica_x25519_ctx_del
ica_x448_ctx_del
ica_ed25519_ctx_del
ica_ed448_ctx_del
AES functions
ica_aes_cbc
ica_aes_cbc_cs
ica_aes_ccm
ica_aes_cfb
ica_aes_cmac
ica_aes_cmac_intermediate
ica_aes_cmac_last
ica_aes_ctr
ica_aes_ctrlist
ica_aes_ecb
ica_aes_gcm
ica_aes_gcm_initialize
ica_aes_gcm_initialize_fips
ica_aes_gcm_intermediate
ica_aes_gcm_last
ica_aes_gcm_kma_ctx_new
ica_aes_gcm_kma_ctx_free
ica_aes_gcm_kma_init
ica_aes_gcm_kma_init_fips
ica_aes_gcm_kma_get_iv
ica_aes_gcm_kma_update
ica_aes_gcm_kma_get_tag
ica_aes_gcm_kma_verify_tag
ica_aes_ofb
ica_aes_xts
ica_aes_xts_ex
TDES/3DES functions
ica_3des_cbc
ica_3des_cbc_cs
ica_3des_cfb
ica_3des_cmac
ica_3des_cmac_intermediate
ica_3des_cmac_last
ica_3des_ctr
ica_3des_ctrlist
ica_3des_ecb
ica_3des_ofb
Information retrieval functions
ica_get_version
ica_get_build_version
ica_get_hw_info
ica_get_msa_level
ica_get_functionlist
FIPS mode functions
ica_fips_status
ica_fips_powerup_tests
ica_get_fips_indicator
ica_allow_external_gcm_iv_in_fips_mode
SIMD support
ica_mp_mul512
ica_mp_sqr512
Deprecated functions
ica_des_cbc
ica_des_cbc_cs
ica_des_cfb
ica_des_cmac
ica_des_cmac_intermediate
ica_des_cmac_last
ica_des_ctr
ica_des_ctrlist
ica_des_ecb
ica_des_ofb
ica_sha1
libica programming definitions
libica constants
Type definitions
Data structures
Return codes
libica tools
icainfo
icastats
Examples
SHAKE-128 example
SHA-256 example
RSA example
AES with CFB mode example
AES with CTR mode example
AES with OFB mode example
AES with XTS mode example
AES with CBC mode example
AES with GCM mode example
CMAC example
ECDSA example
ECDH example
Makefile example
Common Public License - V1.0
All versions
Related materials about security
Service, support, and troubleshooting
Troubleshooting Guide
What's new in edition SC34-2612-08
PDF file
Techniques
Checklist
General problems
Performance problems
Network problems
Hung system problems
Middleware problems
Tools
Assumptions
Authority
sysfs and procfs
debugfs
General tools
dbginfo.sh
sos report
supportconfig
Performance tools
sadc
Start as a service
Start directly
iostat
z/VM MONWRITE
Collect DASD statistics
lnxsv_ts_dasdstat
ziomon
ziorep
ziorep_config
ziorep_utilization
ziorep_traffic
Collect QDIO statistics
Special tools
s390dbf traces
scsi_logging_level
top
hyptop
ps
netstat
ss
Collect QETH statistics
tcpdump
Dump tools
Contact IBM Support
Exchanging information with IBM
Send data to IBM Support
Receiving information
Detect guest relocation
Collect Linux and setup performance data collection
Kernel messages
PDF file for Linux on z Systems kernel messages
Displaying a message man page
IBM Doc Buddy app
aes_s390
aes_s390.cb83bb
aes_s390.dc0a3b
aes_s390.e37463
af_iucv
af_iucv.5c08c7
af_iucv.cc24c0
ap
ap.2e0ad5
ap.3677f7
ap.7564a4
ap.fce52f
appldata
appldata.0ae163
appldata.81e326
appldata.887845
appldata.ccf8e3
appldata.f26e28
bpf_jit
bpf_jit.7b9347
cio
cio.0e0832
cio.0f6270
cio.1c5e61
cio.2943d5
cio.2b995e
cio.390dcf
cio.582533
cio.5b32ec
cio.7a35c2
cio.8665f1
cio.8e4d4c
cio.96a34f
cio.b5d5f6
cio.d25039
cio.e99758
claw
claw.182198
claw.24e119
claw.379c1e
claw.37e392
claw.3a62f0
claw.3f4182
claw.4b316e
claw.50a02b
claw.5355ea
claw.55352b
claw.5bd403
claw.68529a
claw.6c9677
claw.6d0a8f
claw.70b434
claw.70e156
claw.7466e6
claw.74be71
claw.76b4f5
claw.7797f9
claw.7c1758
claw.7f27d6
claw.81d266
claw.823401
claw.858a92
claw.887cf5
claw.89e5ba
claw.9bd9c2
claw.a84a95
claw.a94684
claw.abecae
claw.b13754
claw.b322ac
claw.b40a6a
claw.b85501
claw.c06c67
claw.ce65ab
claw.d99a9c
claw.e52567
claw.f10136
claw.f26e3d
cpcmd
cpcmd.5984fe
cpu
cpu.17772b
cpu.33a262
cpu.3748dd
cpu.643eaf
cpu.e2917c
cpu.f76a91
cpum_cf
cpum_cf.094d6c
cpum_cf.1606b2
cpum_cf.2419af
cpum_cf.74a342
cpum_cf.a9d681
cpum_cf.db48c1
cpum_sf
cpum_sf.13a98c
cpum_sf.20f026
cpum_sf.310c27
cpum_sf.72392d
cpum_sf.856c05
cpum_sf.96d859
cpum_sf.9aaa3d
cpum_sf.a24924
cpum_sf.a2e96f
cpum_sf.d37efd
cpum_sf.d9c8dd
ctcm
ctcm.06c639
ctcm.0e17de
ctcm.3c5812
ctcm.4b5292
ctcm.58aa19
ctcm.8079b5
ctcm.95ba79
ctcm.ad45a0
ctcm.afe161
ctcm.c97a8e
ctcm.defd4f
ctcm.ec4b8d
ctcm.fde68a
dasd-diag
dasd-diag.0ae5e4
dasd-diag.1c9171
dasd-diag.2741d8
dasd-diag.85669c
dasd-diag.b998d3
dasd-diag.c81491
dasd-diag.d0c64e
dasd-diag.e8d084
dasd-diag.eac657
dasd-eckd
dasd-eckd.00f842
dasd-eckd.01a684
dasd-eckd.01f692
dasd-eckd.02c01a
dasd-eckd.0471ed
dasd-eckd.04ae78
dasd-eckd.05b6e3
dasd-eckd.05c8ba
dasd-eckd.06e412
dasd-eckd.07541e
dasd-eckd.08b486
dasd-eckd.08b7b8
dasd-eckd.08d1ee
dasd-eckd.094439
dasd-eckd.0ad5d2
dasd-eckd.0af298
dasd-eckd.0af728
dasd-eckd.0d6cb0
dasd-eckd.0e881a
dasd-eckd.0ec8bb
dasd-eckd.120e7f
dasd-eckd.126bfe
dasd-eckd.1577ff
dasd-eckd.190a3f
dasd-eckd.1bdba7
dasd-eckd.1c04cd
dasd-eckd.1cfbb8
dasd-eckd.1dd1a2
dasd-eckd.1fd065
dasd-eckd.20b59b
dasd-eckd.22e514
dasd-eckd.252dae
dasd-eckd.2567a1
dasd-eckd.27f2cd
dasd-eckd.292792
dasd-eckd.29f189
dasd-eckd.2aa01a
dasd-eckd.2dd933
dasd-eckd.2ebc2e
dasd-eckd.308a03
dasd-eckd.331a2a
dasd-eckd.36ac9b
dasd-eckd.39c600
dasd-eckd.3dd39b
dasd-eckd.3ea257
dasd-eckd.400105
dasd-eckd.412b53
dasd-eckd.4170f2
dasd-eckd.423705
dasd-eckd.423d5b
dasd-eckd.42a207
dasd-eckd.43830c
dasd-eckd.459c47
dasd-eckd.45f2d1
dasd-eckd.46d841
dasd-eckd.47fcac
dasd-eckd.481dec
dasd-eckd.487b65
dasd-eckd.4a5b55
dasd-eckd.4aeb6d
dasd-eckd.4cdcde
dasd-eckd.4dfdcd
dasd-eckd.5005eb
dasd-eckd.538dcc
dasd-eckd.55aa2f
dasd-eckd.5806f8
dasd-eckd.58865b
dasd-eckd.58c328
dasd-eckd.5cf324
dasd-eckd.5efa1b
dasd-eckd.5f55a6
dasd-eckd.637cf1
dasd-eckd.648dca
dasd-eckd.65917e
dasd-eckd.65b8de
dasd-eckd.680aac
dasd-eckd.6e3fdc
dasd-eckd.6eae2d
dasd-eckd.7109ed
dasd-eckd.72eaa3
dasd-eckd.74be4d
dasd-eckd.75ca81
dasd-eckd.767039
dasd-eckd.792e2f
dasd-eckd.7b19bf
dasd-eckd.7bb394
dasd-eckd.7c1681
dasd-eckd.7eabfd
dasd-eckd.7f0765
dasd-eckd.81757d
dasd-eckd.840169
dasd-eckd.869e5e
dasd-eckd.87ddea
dasd-eckd.894a4b
dasd-eckd.8b4bdf
dasd-eckd.90fb0d
dasd-eckd.910d5f
dasd-eckd.91bb3c
dasd-eckd.948ccf
dasd-eckd.96f088
dasd-eckd.9957b7
dasd-eckd.9a48d5
dasd-eckd.9bb776
dasd-eckd.9e183a
dasd-eckd.9f31f9
dasd-eckd.a0ce75
dasd-eckd.a28dc6
dasd-eckd.a3c651
dasd-eckd.a4325c
dasd-eckd.a56dba
dasd-eckd.a77e4f
dasd-eckd.a7b39e
dasd-eckd.a9cbd8
dasd-eckd.aac43a
dasd-eckd.ac3f69
dasd-eckd.ac6397
dasd-eckd.acd228
dasd-eckd.adb621
dasd-eckd.b14557
dasd-eckd.b22b7e
dasd-eckd.b281ed
dasd-eckd.b3193d
dasd-eckd.b3f650
dasd-eckd.b81b6c
dasd-eckd.b98207
dasd-eckd.bba496
dasd-eckd.bbe891
dasd-eckd.bd1a0f
dasd-eckd.be85b8
dasd-eckd.bfc2cb
dasd-eckd.c28ccc
dasd-eckd.c3ebff
dasd-eckd.c55c2f
dasd-eckd.c67479
dasd-eckd.c87cc2
dasd-eckd.c9cc06
dasd-eckd.c9f7f5
dasd-eckd.ca8dfc
dasd-eckd.cf8d3d
dasd-eckd.d1a88a
dasd-eckd.d2af02
dasd-eckd.d2bf98
dasd-eckd.d35646
dasd-eckd.d4a740
dasd-eckd.d4d6d2
dasd-eckd.d608df
dasd-eckd.d66c5d
dasd-eckd.d74b52
dasd-eckd.d7a598
dasd-eckd.d82ca0
dasd-eckd.dc4849
dasd-eckd.dcc26f
dasd-eckd.def9e6
dasd-eckd.e0558d
dasd-eckd.e0679b
dasd-eckd.e181a1
dasd-eckd.e698e6
dasd-eckd.e951ba
dasd-eckd.ec6f52
dasd-eckd.ed1a53
dasd-eckd.f02333
dasd-eckd.f0ba2c
dasd-eckd.f4346b
dasd-eckd.f453eb
dasd-eckd.f4a01e
dasd-eckd.f4ccb9
dasd-eckd.f546ed
dasd-eckd.f58554
dasd-eckd.f59fd6
dasd-eckd.f6f541
dasd-eckd.f716c1
dasd-eckd.f85adb
dasd-eckd.f99a70
dasd-eckd.fba34e
dasd-eckd.fe3f84
dasd-eckd.ffd164
dasd-fba
dasd-fba.680aac
dasd-fba.757950
dasd-fba.f36f2f
dasd
dasd.00f842
dasd.01a684
dasd.01f692
dasd.02c01a
dasd.04422e
dasd.0471ed
dasd.04ae78
dasd.05b6e3
dasd.05c8ba
dasd.06e412
dasd.07541e
dasd.08b7b8
dasd.08d1ee
dasd.094439
dasd.0ad5d2
dasd.0ae5e4
dasd.0af728
dasd.0c0534
dasd.0d6cb0
dasd.0e881a
dasd.1211d0
dasd.126bfe
dasd.1577ff
dasd.157e58
dasd.190a3f
dasd.1ac0f4
dasd.1bdba7
dasd.1c04cd
dasd.1c9171
dasd.1cfbb8
dasd.1dd1a2
dasd.1e2d81
dasd.20b59b
dasd.22e514
dasd.2529f2
dasd.2567a1
dasd.2741d8
dasd.292792
dasd.29f189
dasd.2dd933
dasd.2ebc2e
dasd.2f6a90
dasd.308a03
dasd.331a2a
dasd.34a404
dasd.35e4e6
dasd.39c600
dasd.3dba87
dasd.3dd39b
dasd.3e7d29
dasd.3ea257
dasd.400105
dasd.401b68
dasd.412b53
dasd.423705
dasd.423d5b
dasd.42a207
dasd.43830c
dasd.459c47
dasd.45f2d1
dasd.46d841
dasd.47fcac
dasd.481dec
dasd.487b65
dasd.4a5b55
dasd.4aeb6d
dasd.4cdcde
dasd.4e48d3
dasd.5005eb
dasd.50a6e5
dasd.518c6a
dasd.52d5fe
dasd.5303a1
dasd.538dcc
dasd.55aa2f
dasd.56adec
dasd.5806f8
dasd.58865b
dasd.58c328
dasd.5c0c98
dasd.5cf324
dasd.5efa1b
dasd.648dca
dasd.65917e
dasd.65b8de
dasd.680aac
dasd.68f0f6
dasd.696eb5
dasd.6e3fdc
dasd.6eae2d
dasd.7109ed
dasd.72eaa3
dasd.74be4d
dasd.75373e
dasd.757950
dasd.75ca81
dasd.760a94
dasd.781738
dasd.7854c0
dasd.78e1df
dasd.792e2f
dasd.7b19bf
dasd.7bb394
dasd.7c1681
dasd.7eabfd
dasd.7f0765
dasd.81757d
dasd.840169
dasd.869e5e
dasd.894a4b
dasd.8b4bdf
dasd.8ca077
dasd.90fb0d
dasd.910d5f
dasd.939f75
dasd.948ccf
dasd.966201
dasd.96f088
dasd.9957b7
dasd.9a48d5
dasd.9bb776
dasd.9d6a8a
dasd.9e183a
dasd.9f31f9
dasd.a0ce75
dasd.a28dc6
dasd.a2cf19
dasd.a35e01
dasd.a3baba
dasd.a3bece
dasd.a3c651
dasd.a4325c
dasd.a6cafa
dasd.a77e4f
dasd.a7b0fb
dasd.a9cbd8
dasd.aac43a
dasd.ac3f69
dasd.ac6397
dasd.acd228
dasd.adb621
dasd.b13a1f
dasd.b14557
dasd.b281ed
dasd.b3193d
dasd.b81b6c
dasd.b98207
dasd.b998d3
dasd.bba496
dasd.bba7e6
dasd.bbe891
dasd.bd1a0f
dasd.be85b8
dasd.bfc2cb
dasd.c0aa71
dasd.c1bf11
dasd.c28ccc
dasd.c3ebff
dasd.c533c6
dasd.c55c2f
dasd.c67479
dasd.c81491
dasd.c87cc2
dasd.c9cc06
dasd.c9f7f5
dasd.ca8dfc
dasd.cf8d3d
dasd.d0c64e
dasd.d2af02
dasd.d2bf98
dasd.d303ec
dasd.d35646
dasd.d4a740
dasd.d4d6d2
dasd.d66c5d
dasd.d74b52
dasd.d7a598
dasd.d82ca0
dasd.d84a7b
dasd.da6176
dasd.dcc26f
dasd.de3a76
dasd.df34c6
dasd.e0558d
dasd.e0679b
dasd.e181a1
dasd.e1da4d
dasd.e698e6
dasd.e8d084
dasd.e951ba
dasd.eac657
dasd.ed1a53
dasd.f02333
dasd.f0ba2c
dasd.f453eb
dasd.f4a01e
dasd.f58554
dasd.f59fd6
dasd.f6f541
dasd.f97899
dasd.f99a70
dasd.fba34e
dasd.fc2c31
dasd.ff4c45
dasd.ffd164
dcssblk
dcssblk.0a9a59
dcssblk.14ff71
dcssblk.1e441c
dcssblk.247a44
dcssblk.257c8b
dcssblk.3c90ef
dcssblk.3d858e
dcssblk.50ebd0
dcssblk.6ac195
dcssblk.784873
dcssblk.7b5aa7
dcssblk.9a4530
dcssblk.dd556f
dcssblk.f259b2
dcssblk.f85784
diag288_wdt
diag288_wdt.1b94f3
diag288_wdt.3941b2
diag288_wdt.65bcab
diag288_wdt.684692
diag288_wdt.8ca5c3
diag288_wdt.9f0db9
diag288_wdt.a00fff
diag288_wdt.b3d7fb
diag288_wdt.c1bec2
diag288_wdt.d41079
extmem
extmem.06a5dd
extmem.262f7b
extmem.326775
extmem.584f8e
extmem.6bd595
extmem.7c6a46
extmem.7fb545
extmem.8b00b5
extmem.8e36b2
extmem.972edd
extmem.99ae11
extmem.9e2ee4
extmem.aa62ff
extmem.b8acd6
extmem.c55583
extmem.cb0afe
extmem.d03247
extmem.da1614
extmem.e08a4c
extmem.f0af04
extmem.febf72
hmcdrv
hmcdrv.a3150c
hugetlb
hugetlb.87d848
hvc_iucv
hvc_iucv.09cae6
hvc_iucv.1bc1e0
hvc_iucv.339854
hvc_iucv.5a5e90
hvc_iucv.5bc646
hvc_iucv.691dff
hvc_iucv.9f5b40
hvc_iucv.d4fcff
hvc_iucv.e38b47
hypfs
hypfs.7a79f0
hypfs.7f5705
hypfs.90c29b
hypfs.a2406e
hypfs.cccfb8
iucv
iucv.1d65b1
iucv.beb348
lcs
lcs.23ff8e
lcs.2a7553
lcs.432fb3
lcs.4abb3d
lcs.5d4e1a
lcs.618a07
lcs.64a3d7
lcs.b44620
lcs.c375fd
lcs.e47e1f
lcs.f3f094
monreader
monreader.0111fc
monreader.029e2e
monreader.15a7a1
monreader.1a46fe
monreader.6f04b5
monreader.88c26a
monreader.c042b6
monreader.ca6466
monwriter
monwriter.fcbea9
netiucv
netiucv.04ce63
netiucv.297069
netiucv.55da31
netiucv.56149b
netiucv.5be5dc
netiucv.6b758f
netiucv.863549
netiucv.bcbc54
netiucv.c1b7ef
netiucv.cfb810
netiucv.e9590c
numa
numa.196305
numa_emu
numa_emu.4e9f29
numa_emu.5bb827
numa_emu.84b6f1
os_info
os_info.2fdede
os_info.d3cf4c
perf
perf.2308eb
perf.444429
perf.ad938e
perf.c7b342
perf.ee05c5
prng
prng.21a20e
prng.22c4d8
prng.34ecfd
prng.5a0713
prng.75a4bd
prng.83a5b3
prng.a1c284
prng.a1d3da
prng.e9e54e
qeth
qeth.03aa42
qeth.0634b8
qeth.0650b1
qeth.0815b7
qeth.0d069c
qeth.123aa6
qeth.1d3c1d
qeth.1e4c70
qeth.21a074
qeth.2211d4
qeth.2f18a4
qeth.34318e
qeth.3acf0c
qeth.3ca478
qeth.3d0305
qeth.48d0da
qeth.4a588d
qeth.4da7f2
qeth.531375
qeth.53237e
qeth.5cb8a3
qeth.5d5e5c
qeth.5ff844
qeth.666544
qeth.6adf49
qeth.72880f
qeth.760272
qeth.77cf86
qeth.7ade71
qeth.7fdb9b
qeth.86d925
qeth.883aa0
qeth.8a7bb9
qeth.8aead2
qeth.8c5944
qeth.90d7eb
qeth.96f275
qeth.9b3034
qeth.9e9f31
qeth.a0c0b9
qeth.a4a7ee
qeth.a641db
qeth.a853bd
qeth.aa2df0
qeth.aa55b2
qeth.aafb9d
qeth.ad45e9
qeth.aed751
qeth.bfc665
qeth.c0a93c
qeth.c13293
qeth.c4e1a6
qeth.c98a58
qeth.c9b70b
qeth.cad026
qeth.cc86d9
qeth.ce500a
qeth.d41e42
qeth.d5b6b3
qeth.da9a6a
qeth.db1e5d
qeth.deb9bd
qeth.df0225
qeth.e368d8
qeth.e474f9
qeth.e73874
qeth.eb4e01
qeth.ec9725
qeth.ef9329
qeth.f56315
qeth.f6c89f
qeth.f823af
qeth.faf3f3
qeth.fce5bf
qeth.fd0b7c
qeth.ffe766
s390dbf
s390dbf.2d934d
s390dbf.8e20d2
s390dbf.a1b9ad
s390dbf.ac1eb1
s390dbf.d8734b
s390dbf.ee54db
sclp_cmd
sclp_cmd.4336b4
sclp_cmd.c01fec
sclp_config
sclp_config.12c7a1
sclp_sd
sclp_sd.aa051d
sclp_sd.b12339
sclp_sd.ef2911
scm_block
scm_block.1ab3e5
scm_block.5ab56e
scm_block.81e66f
scm_block.84405e
scm_block.93981a
setup
setup.0471f6
setup.0713cd
setup.0961dd
setup.0cb929
setup.1a06a7
setup.262f23
setup.289988
setup.6bac7a
setup.904d83
setup.9d71f8
setup.a2ec39
setup.b050d0
setup.c5fc0c
setup.d5d221
setup.d96661
setup.dae2e8
setup.db58c7
setup.df70d5
setup.f47455
tape
tape.1e4d72
tape.6e320b
tape.8ce1c3
tape.a6fc3e
tape.aaef3e
tape.bedee0
tape.d10f9d
tape.fbea0c
tape_34xx
tape_34xx.01b705
tape_34xx.0a2df0
tape_34xx.0dcb6e
tape_34xx.1438e6
tape_34xx.150bb7
tape_34xx.15d49e
tape_34xx.1e4d72
tape_34xx.257c56
tape_34xx.2caadc
tape_34xx.33278e
tape_34xx.3be0ed
tape_34xx.3f2d36
tape_34xx.3f38f7
tape_34xx.442701
tape_34xx.553e40
tape_34xx.633cc6
tape_34xx.64dd87
tape_34xx.696dc8
tape_34xx.69f60e
tape_34xx.6bcece
tape_34xx.6e320b
tape_34xx.7f9ae4
tape_34xx.85efa7
tape_34xx.8ce1c3
tape_34xx.956e53
tape_34xx.a6fc3e
tape_34xx.aaef3e
tape_34xx.b334e9
tape_34xx.bedee0
tape_34xx.c5ee4a
tape_34xx.c7fc10
tape_34xx.ccc5ad
tape_34xx.cfc6c4
tape_34xx.d10f9d
tape_34xx.d2b071
tape_34xx.d56330
tape_34xx.d608a6
tape_34xx.e473c9
tape_34xx.e96040
tape_34xx.f06a05
tape_34xx.fbea0c
tape_3590
tape_3590.07e630
tape_3590.18dc29
tape_3590.1e4d72
tape_3590.3c5600
tape_3590.3f6a17
tape_3590.497827
tape_3590.4b2253
tape_3590.575a6b
tape_3590.601044
tape_3590.6e320b
tape_3590.7ad0ac
tape_3590.8ce1c3
tape_3590.991401
tape_3590.a6fc3e
tape_3590.aaef3e
tape_3590.bedee0
tape_3590.d10f9d
tape_3590.fbea0c
tape_3590.fca498
tape_3590.ff1db8
time
time.93fc64
time.c4bd65
time.eb7580
vmcp
vmcp.42661a
vmlogrdr
vmlogrdr.c1d147
vmur
vmur.386675
vmur.4afe2c
vmur.53bf56
vmur.ff8847
vmwatchdog
vmwatchdog.8f03fb
vmwatchdog.bfeb9c
xpram
xpram.9f7762
xpram.ab9aa4
xpram.f004d1
xpram.f6ae78
zcrypt
zcrypt.30eb0a
zcrypt.ce7ec0
zdump
zdump.54a0dd
zdump.aa9461
zdump.d05784
zdump.d448a6
zfcp
zfcp.000866
zfcp.00beaa
zfcp.01a8f2
zfcp.020115
zfcp.058803
zfcp.069af1
zfcp.0cf3fa
zfcp.10efb5
zfcp.128ff1
zfcp.17ac1c
zfcp.19bff2
zfcp.219537
zfcp.25b968
zfcp.29fa1a
zfcp.2a747e
zfcp.2c93b9
zfcp.306272
zfcp.307c0c
zfcp.308f45
zfcp.3c369f
zfcp.3dff9c
zfcp.41ca31
zfcp.4a463f
zfcp.4c0e02
zfcp.4fed50
zfcp.566303
zfcp.56747f
zfcp.574d43
zfcp.5cd78f
zfcp.63f95d
zfcp.646ca0
zfcp.657cf6
zfcp.6dbb23
zfcp.7059a3
zfcp.747e7d
zfcp.772dc6
zfcp.787564
zfcp.79e992
zfcp.7d0b42
zfcp.7d6999
zfcp.7f96f9
zfcp.82bb71
zfcp.87c4d0
zfcp.8a704c
zfcp.8bdb34
zfcp.92ac85
zfcp.9b70c0
zfcp.9d2550
zfcp.9d2a6b
zfcp.a9953d
zfcp.ac341f
zfcp.ad5387
zfcp.afba9a
zfcp.b2d959
zfcp.b2ef0a
zfcp.c0fd29
zfcp.c2c546
zfcp.cf1c58
zfcp.cfb51a
zfcp.d34e30
zfcp.d4aea8
zfcp.dda2e3
zfcp.de56fd
zfcp.e78dec
zfcp.ea662c
zfcp.f16820
zfcp.f4dc96
zpci
zpci.1bc6a2
zpci.9b6a12
Using the Dump Tools
Kernel 7.1
What's new
PDF file
Planning for dumps
Tools overview
kdump
Stand-alone tools
virsh dump
VMDUMP
Live-system dump
Maximum dump size by tool
Dump methods compared
Automatic dump
Test dump-on-panic
Versions
Dumps for secure guests
Using kdump
How kdump works on IBM Z
Setting up kdump
Initiating a dump
KVM guest example
z/VM guest example
LPAR example
Accessing the dump
DASD as dump device
Installing the CCW DASD dump tool
Initiating a DASD dump
From z/VM example
LPAR example
Automatic dump
Copying to file
Using DASD devices for multi-volume dump
Installing the multi-volume DASD dump tool
Initiating a multi-volume DASD dump
Copying to file
DASD list-directed dump
Install list-directed-dump tool
Initiate a list-directed dump
dumpconf example
LPAR example
Copying to file
Print the dump header
Mount the dump
Tape as dump device
Installing the tape dump tool
Initiating a tape dump
z/VM example
HMC or SE example
Copying the dump from tape
Preparing the dump tape
Using the zgetdump tool
Checking whether a dump is valid, and printing the dump header
SCSI disk as dump device
Install SCSI dump tool
Initiate a SCSI dump
From z/VM example
LPAR example
DPM partition example
Automatic dump
Copying to file
Print the dump header
NVMe as dump device
Installing the dump tool
Initiating an NVMe disk dump
LPAR example
DPM partition example
Automatic dump
Copying to file
Print the dump header
Using VMDUMP
Initiate a dump
From z/VM example
Copy the dump to Linux
KVM virsh dump
Create live-system dump
Create the kernel dump
Opening a live-system dump with the crash tool
Processing dumps
Reduce dump size
Compress with makedumpfile
Compressing a dump using gzip and split
Send a dump to IBM
Limit dump size
Commands
The zgetdump tool
The dumpconf service
The crash tool
The vmur tool
zhmc
All versions
Performance
Linux performance white papers
Middleware
Networking
Storage
Compiler
Java
KVM hypervisor
z/VM hypervisor
Red Hat OpenShift on IBM Z and IBM LinuxONE - Performance
Performance archive
Tuning hints and tips
Compiler
CPU hotplug
CPU time accounting
Database server
Disk I/O
Distributions
File systems
IBM Z
Java
Mail Server Lotus Domino
Memory Management
Middleware
Enterprise Content Management
WebSphere Application Server
Networking
Resource management & analysis
Security & cryptography
Systems management
Virtualization
KVM
Linux under z/VM
Base operating system
File systems
IBM Enterprise Content Management for Linux on z Systems, Scale-Out Case Study (Part 1): Single ECM Node with XFS and IBM Spectrum Scale 4.2
About this publication
Notational conventions
Introduction
Objectives of this white paper
IBM Enterprise Content Management
IBM FileNet P8 Content Platform Engine
IBM Content Navigator
IBM Spectrum Scale Version 4.2
XFS filesystem
Summary
Description of the SUT used with Part 1
Hardware and software configuration of the SUT
IBM z Systems server
Networking setup
IBM storage subsystem setup
Linux virtual machines
IBM ECM server
IBM HTTP Server
IBM DB2 ECM database server
WAS Deployment Manager
IBM Tivoli Directory Server
Workload generator for ICN
Setting up and tuning the SUT
Setting up z/VM
Setting up the virtual network
Setting up HyperPAV
Setting up the Linux operating system
Setting up the network
Setting the buffer count
Setting up the disk I/O
Using HyperPAV for ECKD DASD
FCP Hardware Data Router support
Linux Device Mapper-Multipathing (DM-MP)
Other Linux operating system adaptions
Tuning the ECM gateway
Maximum number of network clients for IBM HTTP Server
Enterprise Content Management application tuning
Common WebSphere Application Server tuning
Thread Pool WebContainer
Object Request Broker services
Java Database Connectivity connection pools
WebSphere Application Server Java virtual machine
IBM FileNet P8 Content Platform Engine (CPE)
IBM Content Navigator
Enterprise Content Management database server
DB2 workload type
DB2 database configuration
Database indexing
Example of database indexing
Results of Enterprise Content Management tuning
Enterprise Content Management workload
FileNet Advanced File Storage Area
Advanced File Storage Area on an XFS filesystem
Advanced File Storage Area on Spectrum Scale
IBM Spectrum Scale tuning parameters
Linux system clock synchronization
IBM Spectrum Scale cache usage
Setting the maxFilesToCache parameter
Setting the pagepool size
Relation between pagepool size and level of maxFilesToCache
Setting the value of maxStatCache
Memory consideration for IBM Spectrum Scale cache usage
IBM Spectrum Scale filesystem parameters
Setting the value of blocksize
Setting a value for the number of inodes
Single Enterprise Content Management (ECM) node results
Enterprise Content Management user scaling for XFS
Transaction throughput and z/VM total CPU load
Average ICN transaction response times
ECM user scaling for IBM Spectrum Scale single node cluster
Average ICN transaction response times
FileNet file storage area disk I/O
z/VM total CPU load for the ECM system
Multiple ECM node setup with Spectrum Scale 4.2 (Part 2 white paper)
References
Notices
Trademarks
Terms and conditions
IBM Enterprise Content Management for Linux on z Systems, Scale-Out Case Study (Part 2): Multiple ECM Nodes with IBM WebSphere Application Server Cluster and Spectrum Scale 4.2
About this publication
Notational conventions
Introduction
Objectives of this white paper
IBM Enterprise Content Management
IBM FileNet P8 Content Platform Engine
IBM Content Navigator
IBM Spectrum Scale Version 4.2
WAS clusters
Summary
Description of the SUT used with Part 2
Hardware and software configuration of the SUT
IBM z Systems server
IBM storage subsystem setup
Networking setup
Linux virtual machines
IBM ECM servers
Spectrum Scale NSD servers
IBM HTTP Server
IBM DB2 ECM database server
WAS Deployment Manager
IBM Tivoli Directory Server
Workload generator for ICN
Setting up and tuning the SUT
Managing the WAS cluster workload
Web server request routing
Round robin option (the default)
Random option
ECM WAS cluster with Spectrum Scale
Important Spectrum Scale parameters
Spectrum Scale node quorum
Spectrum Scale node designations
Spectrum Scale cluster configurations
Shared Disk (SD)
Network Shared Disk (NSD)
Comparison of SD and NSD
Spectrum Scale network block I/O
Jumbo frames
Results of network block I/O tuning
ECM workload
Scale-out study results
ECM user scaling for Spectrum Scale SD
Transaction throughput and average ICN response time
CPU loads for ECM nodes
Disk I/O for ECM nodes
ECM user scaling for Spectrum Scale NSD
Single ECM node with XFS and Spectrum Scale 4.2 (Part 1 white paper)
References
Notices
Trademarks
Terms and conditions
Oracle Cluster File System Version 1.2, shared file system for Linux on IBM System z
Introduction
About OCFS2
Overview of OCFS2
History of OCFS2
Versatility of OCFS2
Systems and connection methods for OCFS2
Storage server and disk configuration for OCFS2
The O2CB heartbeat and services stack
Installing and customizing OCFS2
Installing OCFS2 packages
Creating the OCFS2 cluster environment
Controlling O2CB with the /etc/init.d/o2cb utility
Preparing disks for use with OCFS2
Starting OCFS2 at system restart time
Mounting shared devices and using the /etc/fstab file
Maintaining OCFS2
Managing shared disks
Another device naming technique
Too many DASDs accessible to Linux for read
Bibliography
Notices
Trademarks
Terms and conditions
Disk storage
Linux on System z: iSCSI Initiator Configuration
About this publication
Introduction
iSCSI initiators and targets
Generating an iSCSI qualified name
Setting up iSCSI at the Storwize V7000 clustered system
Creating an iSCSI host on Storwize V7000
Mapping iSCSI volumes to the iSCSI host on the Storwize V7000 system
Setting up iSCSI initiator software on Linux on System z
Installing iSCSI initiator software on Linux on System z
Setting the iSCSI qualified name for the Linux host
Discovering iSCSI targets using Send Targets
Logging in to discovered targets
Logging out from targets
Discovering and logging in to targets using YaST (SUSE-specific)
Logging out from iSCSI targets using YaST (SUSE-specific)
Automatic iSCSI target discovery and login (persistent across subsequent reboots)
Avoiding data corruption or loss
References
Linux on KVM
Exploiting HiperSockets in a KVM Environment Using IP Routing with Linux on Z - Results and Findings
About this publication
Notational conventions
Overview
Introduction
Objectives
Findings summary
Test environment
System configurations
Operating system installation
KVM host network configurations
KVM guest virtual network configuration using MacVTap
KVM guest virtual network configuration using Open vSwitch
Modifying the kernel command line parameters
Configuring HiperSockets in Linux LPARs
Routing traffic from the KVM guest to other LPAR and back
Subnet definitions in the HiperSockets configuration
KVM guest routing rule configuration
Other LPAR routing rule configuration
The network workload
Workload tests description
Workload tests identification
Testing methodology
Other configuration considerations: Optimal MTU size
Results comparison of HiperSockets versus OSA
References
Notices
Trademarks
Terms and conditions
IBM Z: Network Storage Protocols in a KVM Environment NFS/SMB/iSCSI Report
About this publication
Notational conventions
Abstract
Summary
Network tuning recommendations
Sequential workloads
Random workloads
Setup
Hardware setup
IBM Z LPAR
IBM Storwize V7000
KVM host and guest sizing
Software setup
KVM host software
KVM guest software
Protocol server software
Environment setup
Storage setup
XFS file system
QEMU image
I/O threads
Network setup
Storage protocols and transports
NFS
NFS server setup
NFS client setup
SMB
SMB server setup
SMB client setup
iSCSI client setup
FIO workload
Measurements
Sequential read
Comparison sequential read
iSCSI sequential read
NFS sequential read
SMB sequential read
Sequential write
Comparison sequential write
iSCSI sequential write
NFS sequential write
SMB sequential write
Random read
Comparison random read
iSCSI random read
NFS random read
SMB random read
Random write
Comparison random write
iSCSI random write
NFS random write
SMB random write
References
Notices
Trademarks
Terms and conditions
Linux on z/VM
IBM z/VM 6.3 HiperDispatch - Polarization Modes and Middleware Performance
Introduction
Summary
Hardware and software configurations
Host system setup
Software system setup
Overview of the test environment
Test Methodology
Test workloads
How the z/VM Performance Toolkit was used
Overview of z/VM HiperDispatch
CPU MF (Measurement Facility)
Guest dispatching metrics
Workload performance metrics
Test results
z/VM 6.3 and the z13 exploitation SPE APAR VM65586
SRM polarization and guest CPU waits
References
z/VM 6.3 Resource Overcommitment
Introduction
Objectives
Notation conventions
Executive summary
Summary
Hardware and software configuration
Hardware
Software
z/VM host configuration
Virtual system configuration
Test approach
Test workloads
Test configurations
Test procedure
Test metrics
Overcommitment considerations
Memory overcommitment
Memory virtualization parameters
Test results
Comparison of z/VM environments
Workload analysis
Reference result
Scaling memory and processors
Database BI workload
Transactional WAS workload
File system I/O workload
Java workload
Network workload
References
IBM Cognos Business Intelligence 10.2.1 for Linux on System z - Performance and z/VM Resource Management
Introduction
Summary
System under test - overview
Hardware and software configurations
IBM System z Enterprise 196 z/VM LPAR setup
IBM storage subsystem setup
Network Setup
Cognos BI Server virtual machines (distributed installation)
DayTrader benchmark application server virtual machines
Client machine used as workload driver
System under test - setup and tuning
z/VM setup
Linux operation system setup
Cognos BI Gateway
Cognos BI application tier
Cognos BI Content Manager and DB2 Content Store
Workload descriptions
Cognos BI workload
DayTrader benchmark application
Results
z/VM fair share setup
VMRM parameters
VMRM - managing workload peaks
References
z/VM 6.2 Live Guest Relocation with Linux Middleware - Various Workloads
Introduction
Objectives
Summary
Hardware and software configuration
Hardware
Software
z/VM configuration
Linux guest configuration
Test approach
Test workloads
Java workload
File system I/O workload
Direct parameter
Rate parameter
Transactional database workload
Mixed workload
Test metrics
Test results
Reference workload - Java workload
File system I/O workload
File system I/O workload – scaling the fio throughput for page cache I/O
Observation
Conclusion
File system I/O workload - scaling the fio throughput for direct I/O
Observation
Conclusion
File system I/O workload - influence of the fio throughput on quiesce time
Observation
Conclusion
Transactional database workload
Transactional database workload - scaling the Linux guest size and Oracle Database target memory
Observation
Conclusion
Transactional database workload - scaling the number of SwingBench users
Observation
Conclusion
Various workloads - number of memory passes and amount of data transferred
Observation
Conclusion
Curing CPU constraints by offloading guests with high CPU load
Mixed workload – analysis of the CPU usage of the relocated transactional database workload
Observation
Conclusion
Mixed workload – analysis of the CPU usage of the other workloads on the source z/VM system
Observation
Conclusion
References
z/VM 6.2 Live Guest Relocation with Linux Middleware
Introduction
z/VM 6.2
Relocation concepts
Objectives
Summary
Hardware and software configuration
Server hardware
System z – LPAR Configuration
Storage server - DS8K15
IOCDS configuration for FICON CTCs
Server software
z/VM and Linux configuration
z/VM configuration
ISFC logical link configuration
General
Avoidance of write collisions
Linux guest configuration
z/VM monitor configuration
Test approach
Test sequence
Test workload
Test configurations
ISFC logical link configurations with "straight" FCTC connections
ISFC logical link configurations with "crossed" FCTC connections
Striping of FCTC device numbers
Test metrics
Test results
General
Performance of the relocation process
Baseline test
Scaling the number of FCTC connections per ISFC logical link
ISFC logical link configuration with one shared FICON channel and "straight" FCTC connections
ISFC logical link configuration with two shared FICON channels and "straight" FCTC connections
ISFC logical link configuration with three shared FICON channels and "straight" FCTC connections
ISFC logical link configuration with two shared FICON channels and "crossed" FCTC connections
ISFC logical link configuration with three shared FICON channels and "crossed" FCTC connections
ISFC logical link configuration with two non-shared FICON channels and "crossed" FCTC connections
ISFC logical link configuration with four non-shared FICON channels and "crossed" FCTC connections
Scaling the number of FICON channels per ISFC logical link
Influence of striping of FCTC devices numbers over FICON channels
Common observations
Linux guest performance during the relocation process
Number of memory passes
z/VM system load during the relocation process
ISFC logical link performance
ISFC logical link data rates
FCTC connection I/O rates
Influence of striping of FCTC devices numbers over FICON channels
FCTC connection I/O rates for non-shared ISFC logical link configurations
Recommendations
IOCDS example
Using the Linux cpuplugd Daemon to manage CPU and memory resources from z/VM Linux guests
Objectives
Executive summary
Summary
CPU plugging
Memory plugging
Hardware and software configuration
Server configuration
Client configuration
Workload description
DayTrader
WebSphere Studio Workload Simulator
z/VM and Linux setup
WebSphere environment
WebSphere Studio Workload Simulator configuration
Java heap size
Database configuration
z/VM settings
Linux guests
Results
Methodology
Manual sizing
Monitoring cpuplugd management behavior
Understanding sizing charts
cpuplugd configuration rules
CPU plugging
loadavg-based
Real CPU load-based
Memory plugging
General considerations regarding cpuplugd rules for memory management
Optimizing for throughput
More details about Linux memory size and throughput
Minimizing memory size
More details about Linux memory size and throughput
Dynamic runs
Setup tests and variations
Scaling the cpuplugd update interval
Memory plugging and steal time
Tuning scripts
DB2 UDB tuning
WebSphere tuning script
Sample configuration files
Recommended default configuration
CPU plugging via loadavg
CPU plugging via real CPU load
Memory plugging configuration 1
Memory plugging configuration 2
Memory plugging configuration 3
Memory plugging configuration 4
Memory plugging configuration 5
Memory plugging configuration 7
Memory plugging configuration 8
Memory plugging configuration 9
Memory plugging configuration 10
References
Notices
Trademarks
Terms and conditions
WebSphere Application Server Horizontal versus Vertical JVM Stacking Report
Introduction
Summary
Test environment
System setup
Workload description
Test methodology and scenarios
Measurement results
Test scenario 1: Guest scaling
Test scenario 2: Varying the number of virtual CPUs for 20 guests
Test scenario 3: Varying the number of virtual CPUs for 200 guests
Test scenario 4: Virtual CPU scaling and WebSphere threads
Setup tests
Setup test 1: Large guests
Setup test 2: Using a shared minidisk for WebSphere binaries with and without MDC
Reference
Notices
Trademarks
Terms and conditions
Methods to pause a z/VM guest: Optimize the resource utilization of idling servers
Note
About this publication
Introduction
Summary
Test environment
System setup
Workload description
Scenarios for suspend and resume testing
Results
Test case 1: Elapsed times to pause and restart a guest
Test case 2: Pausing z/VM guests with memory pressure
CPU load analysis
Scheduling status of the guests (Systems of interest)
Location of the guest memory pages (real storage or XSTOR)
Using z/VM STOP and BEGIN method
Additional test case: Resume time of larger guests
Notices
Trademarks
Terms and conditions
z/VM virtualization performance
Introduction to the z/VM virtualization performance tests
Hardware equipment and software environment for the z/VM virtualization tests
Environment
Workload description
System setup for the z/VM virtualization tests
Collecting the output for the z/VM virtualization tests
Results for the z/VM virtualization tests
Scaling triplets with and without SSL with software encryption
Response Times
Quick dispatch (QUICKDSP)
FCP Adapter Load
z/VM guest statistics: working set size and CPU overhead
Detailed set up examples for the z/VM virtualization tests
Configure IBM WebSphere Application Server to accept SSL requests
WebSphere Studio Workload Simulator sample script file
WebSphere sample tuning script
DB2 UDB sample tuning script
WebSphere Studio Workload Simulator sample configuration file
z/VM directory templates for Linux guests
Other sources of information for the z/VM virtualization tests
Notices for the z/VM virtualization tests
z/VM Large Memory - Linux on System z
Introduction to the z/VM large memory tests
Summary for the z/VM large memory tests
Hardware equipment and software environment for the z/VM large memory tests
Test environment
Setup for the z/VM large memory tests
Collaborative Memory Management Assist (CMMA)
VM Resource Manager Cooperative Memory Management (VMRM-CMM)
Workload description
CPU utilization charts for the z/VM large memory tests explained
Results for the z/VM large memory tests
Scale guests into memory overcommitment on z/VM 5.2
Scale guests into memory overcommitment on z/VM 5.3
Comparison of z/VM 5.3 versus z/VM 5.2
Cooperative Memory Management and Collaborative Memory Management Assist Results
Other sources of information for the z/VM large memory tests
Notices for the z/VM large memory tests
Security
Configuring an Apache mod_nss server to exploit z Systems cryptographic hardware
About this publication
Introduction
Prerequisite tasks
Installing the required packages
Loading the zcrypt device driver
Configuring the openCryptoki ica token
Disabling the firewall and SELinux
Checking that the prerequisite tasks were successfully completed
Creating an nss certificate database
Creating a directory for the nss database
Adding the openCryptoki module to the nss database
Create a self-signed CA server certificate
Create a certificate request file
Create a server certificate issued by own Certificate Authority
Import a server certificate into the ica token
Configure and start the Apache HTTPS server
Verifying that cryptographic operations work correctly
Completing the configuration
Enabling the firewall
Enabling SELinux
Checking that the Apache HTTPS server and SELinux work together
Appendix. SELinux policy module
Notices
Trademarks
Terms and conditions
IBM Websphere Application Server Version 8 SSL Performance for Linux on System z
About this publication
Introduction
IBM Websphere Application Server Version 8
IBM System z cryptographic hardware features
Objectives
Summary
IBM System z hardware and software used
IBM Websphere Application Server
Database server
Client used as workload driver
System under test (SUT) overview
Scenario 1: IBM WebSphere Application Server with internal HTTP transport
Scenario 2: IBM WebSphere Application Server with IBM HTTP server transport
Benchmark application description
DayTrader
IBM WebSphere Studio Workload Simulator
Preparing the DB2 database server
Installation requirements
Kernel parameter requirements
DB2 database server network setup
Tuning I/O to a single DASD volume
Setting up and tuning DB2
Setting DB2 profile variables
Using the DB2 autoconfigure command to configure database parameters
Setting the DB2 buffer pool size
Preparing the IBM WebSphere Application Server Version 8
IBM WebSphere Application Server installation requirements
Linux kernel parameter requirements
IBM WebSphere Application Server Network setup
Configuring the IBM WebSphere Application Server
IBM Linux on System z cryptographic setup for the IBM WebSphere Application Server SSL support
IBM System z characteristics
Linux packages required
IBM Linux on System z zcrypt device driver
CP Assist for Cryptographic Function (CPACF) support
Starting the slot manager daemon for openCryptoki – pkcsslotd
Configuring the PKCS#11 cryptographic ICA token
Scenario 1: IBM WebSphere Application Server with internal HTTP transport SSL setup
Updating the Java JCE policy files
Configuring the IBM WebSphere Application Server security custom property forceSoftwareJCEProviderForLTPA
Configuring the IBMPKCS11Impl provider
Adding the user to the PKCS11 group
Selecting IBM WebSphere Application Server cipher suites
SSL certificate key sizes and key management
Checking the cryptographic setup
Scenario 2: IBM WebSphere Application Server with IBM HTTP server transport SSL setup
IBM HTTP server certificate management
Stashing the PKCS#11 cryptographic ICA token user PIN
Adding the IBM HTTP server user to the pkcs11 group
Configuring IBM HTTP server SSL support
Checking the cryptographic setup
SSL performance results
Results for scenario 1: IBM WebSphere Application Server internal HTTP transport
RSA key size 2048-bit
RSA key size 4096-bit
Results for scenario 2: IBM HTTP server
RSA key size 2048-bit
RSA key size 4096-bit
References
Exploiting IBM System z cryptographic hardware using Java Secure Socket Extension
Introduction
Objectives
Summary
Hardware and software configuration
System setup
Environment
Network setup
JSSE setup
Required RPMs to install for JSSE, OpenSSL and Cryptographic functions
Cryptographic hardware configuration
IBM Crypto Express2 feature configuration
openCryptoki configuration
Access to the Java executables and cryptographic libraries
Set up the java.security file for hardware encryption
PKCS11 configuration file
Start the daemons
Setup the openCryptoki password
Prepare libraries for the iKeyman utility
Define a keystore for hardware encryption using the iKeyman utility
Java Version 6.0 migration considerations
Examine the /proc/driver/z90crypt file
Enabling the polling thread for the z90crypt device driver
Configuring the environment to use software encryption
Set up the java.security file for software encryption
Prepare libraries for the iKeyman utility
Define a keystore for software encryption using the iKeyman utility
Workload description
Variations
Workload output and performance data
Results
Java 1.5 SR 9 JSSE software and hardware comparison
Java 1.5 SR 9 JSSE hardware encryption with and without the z90crypt device driver polling thread
Java 1.5 SR 9 JSSE SSL logon method comparison
Java release to release comparisons
Results tables
Bibliography
Notices
Trademarks
Terms and conditions
Tivoli WebSEAL - Sizing and capacity planning
Objectives for the Tivoli WebSEAL performance tests
Summary for the Tivoli WebSEAL performance tests
Hardware equipment and software environment for the Tivoli WebSEAL performance tests
Test environment
Test case setup for the Tivoli WebSEAL performance tests
Benchmark scenarios
WebSEAL setup
Web pages
System z9 cryptographic hardware
Data collection and output
Results for the Tivoli WebSEAL performance tests
Non-SSL page access through a TCP junction, unauthenticated
SSL page access through a TCP junction
SSL page access through a TCP junction with “-c all” option
SSL page access through an SSL junction
SSL page access with new authentication and new SSL session every request
Detailed set up examples for the Tivoli WebSEAL performance tests
Other sources of information for the Tivoli WebSEAL performance tests
Notices for the Tivoli WebSEAL performance tests
Performance of a webApp.secure Environment
Objectives for the webApp.secure performance tests
Summary for the webApp.secure performance tests
Hardware equipment and software environment for the webApp.Secure performance tests
Test environment
Setting up the DMZ - firewall rules
webApp.secure overview
Test case setup for the webApp.secure performance tests
Results for the webApp.secure performance tests
Scaling virtual CPUs on the webApp.secure guests
Varying physical CPUs on z/VM
Detailed set up examples for the webApp.secure performance tests
Firewall iptables rules
Glossary for the webApp.secure performance tests
Other sources of information for the webApp.secure performance tests
Notices for the webApp.secure performance tests
Middleware
IBM Cognos software
IBM Cognos Business Intelligence 10.2.1 for Linux on System z - Performance and z/VM Resource Management
Introduction
Summary
System under test - overview
Hardware and software configurations
IBM System z Enterprise 196 z/VM LPAR setup
IBM storage subsystem setup
Network Setup
Cognos BI Server virtual machines (distributed installation)
DayTrader benchmark application server virtual machines
Client machine used as workload driver
System under test - setup and tuning
z/VM setup
Linux operation system setup
Cognos BI Gateway
Cognos BI application tier
Cognos BI Content Manager and DB2 Content Store
Workload descriptions
Cognos BI workload
DayTrader benchmark application
Results
z/VM fair share setup
VMRM parameters
VMRM - managing workload peaks
References
WebSphere Application Server
IBM Websphere Application Server Version 8 SSL Performance for Linux on System z
About this publication
Introduction
IBM Websphere Application Server Version 8
IBM System z cryptographic hardware features
Objectives
Summary
IBM System z hardware and software used
IBM Websphere Application Server
Database server
Client used as workload driver
System under test (SUT) overview
Scenario 1: IBM WebSphere Application Server with internal HTTP transport
Scenario 2: IBM WebSphere Application Server with IBM HTTP server transport
Benchmark application description
DayTrader
IBM WebSphere Studio Workload Simulator
Preparing the DB2 database server
Installation requirements
Kernel parameter requirements
DB2 database server network setup
Tuning I/O to a single DASD volume
Setting up and tuning DB2
Setting DB2 profile variables
Using the DB2 autoconfigure command to configure database parameters
Setting the DB2 buffer pool size
Preparing the IBM WebSphere Application Server Version 8
IBM WebSphere Application Server installation requirements
Linux kernel parameter requirements
IBM WebSphere Application Server Network setup
Configuring the IBM WebSphere Application Server
IBM Linux on System z cryptographic setup for the IBM WebSphere Application Server SSL support
IBM System z characteristics
Linux packages required
IBM Linux on System z zcrypt device driver
CP Assist for Cryptographic Function (CPACF) support
Starting the slot manager daemon for openCryptoki – pkcsslotd
Configuring the PKCS#11 cryptographic ICA token
Scenario 1: IBM WebSphere Application Server with internal HTTP transport SSL setup
Updating the Java JCE policy files
Configuring the IBM WebSphere Application Server security custom property forceSoftwareJCEProviderForLTPA
Configuring the IBMPKCS11Impl provider
Adding the user to the PKCS11 group
Selecting IBM WebSphere Application Server cipher suites
SSL certificate key sizes and key management
Checking the cryptographic setup
Scenario 2: IBM WebSphere Application Server with IBM HTTP server transport SSL setup
IBM HTTP server certificate management
Stashing the PKCS#11 cryptographic ICA token user PIN
Adding the IBM HTTP server user to the pkcs11 group
Configuring IBM HTTP server SSL support
Checking the cryptographic setup
SSL performance results
Results for scenario 1: IBM WebSphere Application Server internal HTTP transport
RSA key size 2048-bit
RSA key size 4096-bit
Results for scenario 2: IBM HTTP server
RSA key size 2048-bit
RSA key size 4096-bit
References
WebSphere Application Server Horizontal versus Vertical JVM Stacking Report
Introduction
Summary
Test environment
System setup
Workload description
Test methodology and scenarios
Measurement results
Test scenario 1: Guest scaling
Test scenario 2: Varying the number of virtual CPUs for 20 guests
Test scenario 3: Varying the number of virtual CPUs for 200 guests
Test scenario 4: Virtual CPU scaling and WebSphere threads
Setup tests
Setup test 1: Large guests
Setup test 2: Using a shared minidisk for WebSphere binaries with and without MDC
Reference
Notices
Trademarks
Terms and conditions
WebSphere on IBM System z 64-bit and 31-bit studies with J2EE workloads
Introduction
Hardware and software configuration
Server hardware and software - LPAR
Client hardware and software
System setup
Environment
Network setup
Workload generator systems
Linux kernel settings
WebSphere Application Server Linux kernel settings
Enabling 31-bit WebSphere Application Server on IBM System z to use 1 GB JVM
Setting swappiness parameter to zero
Linux kernel settings for the workload generator systems
Linux kernel settings for the DB2 Universal Database system
Setting up WebSphere and DB2 Universal Database
WebSphere V6.1.0 configuration
Java DataBase Connectivity connection pools
Java DataBase Connectivity data source properties
Object Request Broker thread pool
WebContainer thread pool
Default thread pool
HTTP transport settings
Enterprise Java Beans cache settings
Tune the Java Virtual Machine properties
Other Java Virtual Machine arguments
Transaction service properties
Disable Java 2 security
DB2 V9.5 configuration
Initial database setup
Tuning the populated database
DB2 autoconfigure command
Workload description
Results
Heapsize for the 64-bit Java Virtual Machine
Comparing 64-bit WebSphere versus 31-bit WebSphere
CPU scaling study
Database LPAR analysis
Network study – 1 Gb Ethernet versus 10 Gb Ethernet
Configuration, tuning, and performance scripts
Notices
Trademarks
Terms and conditions
End-to-End Performance of a WebSphere Environment Including Edge Components
Introduction to the WebSphere environment performance tests
Summary for the WebSphere environment performance tests
Hardware equipment and software environment for the WebSphere environment performance tests
Environment
Workload description
WebSphere Studio Workload Simulator
Caching proxy server
WebSphere Load Balancer
System setup for the WebSphere environment performance tests
WebSphere Application Server cluster setup
Caching proxy server setup
Dynamic caching with Trade and WebSphere
MaxSocketsPerServer and ServerConnTimeout parameters
z/VM setting QUICKDSP
z/VM Guest LAN type setup
Results for the WebSphere environment performance tests
Single WebSphere Application Server
Varying Trade caching modes
Varying virtual CPUs on the WebSphere Application Server
Varying WebSphere Application Server dynamic cache size
Varying Trade clients
Modifying the z/VM guest LAN type
WebSphere Application Server cluster
Varying WebSphere Application Server nodes without caching
Detailed set up examples for the WebSphere environment performance tests
WebSphere setup
Enabling a second WebSphere as a server within a cluster
Trade setup
Firewall setup
WebSphere Load Balancer setup
WebSphere Studio Workload Simulator script
Web.xml
Cachespec.xml
ibmproxy.conf
Glossary for the WebSphere environment performance tests
Other sources of information for the WebSphere environment performance tests
Notices for the WebSphere environment performance tests
Tuning WebSphere Application Server Cluster with Caching
Introduction to tuning the WebSphere Application Server cluster with caching
Summary for the WebSphere Application Server cluster with caching tests
Benefits of using z/VM
Hardware equipment and software environment
Host hardware
Network setup
Storage server setup
Client hardware
Software (host and client)
Overview of the Caching Proxy Component
WebSphere Edge Components Caching Proxy
WebSphere Proxy Server
Configuration and test environment
z/VM guest configuration
Test environment
Firewall Rules
Workload description
Caching overview
Where caching is performed
DynaCache technical overview
Features of DynaCache
Caching servlets and JSPs
Java objects and the command cache
Data replication service
Setting up and configuring caching in the test environment
Caching proxy server setup
Dynamic caching with Trade and WebSphere
Enabling WebSphere Application Server DynaCache
CPU utilization charts explained
Test case scenarios and results
Test case scenarios
Baseline definition parameters and results
Vary caching mode
Vary garbage collection policy
Vary caching policy
Vary proxy system in the DMZ
Scaling the size of the DynaCache
Scaling the update part of the Trade workload
Enabling DynaCache disk offload
Comparison between IBM System z9, type 2094–S18 and IBM System z10, type 2097–E26
Using z/VM VSWITCH
Detailed setup examples
web.xml setup examples
cachespec.xml setup examples
Other sources of information for the Tuning WebSphere Application Server Cluster with Caching
Trademarks
WebSphere Application Server 6.1 Base Performance
Introduction to the WebSphere Application Server performance tests
Summary for the WebSphere Application Server performance tests
Hardware and software configuration for the WebSphere Application Server performance tests
Environment
Workload description - Trade
Tools description
System setup for the WebSphere Application Server performance tests
Changing buffer settings of the network interfaces
WebSphere Studio Workload Simulator client setup
Configuring the xpram device on RHEL
Collecting the output
Results for the WebSphere Application Server performance tests
WebSphere Application Server release to release comparison
RHEL 4.5 Trade tuning variations
RedHat RHEL release to release comparison
RHEL 5.0 scalability
Other sources of information for the WebSphere Application Server performance tests
WebSphere Application Server Base Performance
Introduction to the WebSphere Application Server performance tests
Summary for the WebSphere Application Server performance tests
Hardware and software configuration for the WebSphere Application Server performance tests
Environment
Workload description - Trade
System setup for the WebSphere Application Server performance tests
WebSphere Studio Workload Simulator client setup
Database setup
WebSphere Application Server setup
Results for the WebSphere Application Server performance tests
Separating the network streams
Modify the database layout
Modify logging setup
Disable AIO for WebSphere Application Server
Workload generation
WebSphere Application Server version 6.0.2 versus version 6.1
DB2 v8 versus DB2 v9
SLES9 versus SLES10
WebSphere Application Server 31-bit versus 64-bit
OSA card versus HiperSockets
Other sources of information for the WebSphere Application Server performance tests
Notices for the WebSphere environment performance tests
Oracle Database
Oracle Database on Linux on System z – Disk I/O Connectivity Study
Introduction
Objectives
Executive summary
Summary
Hardware and software configuration
Server configuration
Client configuration
Workload description
Linux and database setup
HyperPAV
Multipath setup
Monitoring tools
Database setup: the Oracle Automatic Storage Manager
Configuring DASD for ASM
Setting the disk ownership and access permission (DASD and FCP disks)
ASM start
Results
DASD devices
Oracle 10g: scaling the SGA size
Oracle 10g: disk setup for logs and data devices
Oracle 10g: user scaling
Oracle 11g versus Oracle 10g
Oracle 11g: using HyperPAV devices
FCP devices
Oracle 11g: multipath daemon - options
Comparing FCP and ECKD disk devices
Summary: comparing FCP and ECKD disk devices
References
Oracle Real Application Clusters on Linux on IBM System z: Set up and network performance tuning
Note
About this publication
Introduction
Summary
Hardware environment
IBM System z hardware used in the Oracle RAC study
Client hardware
Network setup
Software used in the Oracle RAC study
About Oracle RAC on Linux on IBM System z
History of Oracle RAC
Reasons to use Oracle RAC on IBM System z
Components of Oracle RAC
The Oracle Cluster Registry and the Voting Disk
Oracle RAC operation modes
Planning
Planning to set up Oracle RAC on IBM System z
Shared disk management
Planning to build an Oracle RAC system
Installation and configuration
Preparing Linux for the installation of Oracle RAC
Installing Oracle RAC binaries
Oracle clusterware (CRS)
Installing the Oracle relational database
Installing the Oracle Automatic Storage Manager
Customize the Oracle RAC system
Client side load balancing
Workload
Results
Cluster file system OCFS2 versus Oracle Automatic Storage Management
Cluster Contention - default block size
Dedicated server versus shared server processes
Network Setup - buffer counts
Network Setup - MTU size
Network setup - device queue length
Network Setup - interconnect network device type
References
Notices
Trademarks
Terms and conditions
Performance of an Oracle 10g R2 Database Import Environment
Environment setup
The performance view of the import process
Architecture comparison
Summary
Trademarks
DB2
Performance of environments using DB2 Connect Enterprise Edition
Introduction to the DB2 Connect performance tests
Summary for the DB2 Connect performance tests
Hardware equipment and software environment for the DB2 Connect performance tests
Test environment
Workload description
Setup for the DB2 Connect performance tests
Connection monitoring and CPU utilization charts for the DB2 Connect performance tests explained
Results for the DB2 Connect performance tests
Trade 6 results
Scaling DB2 Connect memory
Scaling DB2 Connect virtual CPUs
Scaling DB2 Connect parameter MAXAGENTS
Compare DB2 Connect to non-DB2 Connect
IRWW results
Scaling DB2 Connect memory
Scaling DB2 Connect CPUs
Scaling DB2 Connect MAXAGENTS
Comparison of SQLJ versus JDBC
Compare DB2 Connect to non-DB2 Connect
Detailed set up examples for the DB2 Connect performance tests
Other sources of information for the DB2 Connect performance tests
Notices for the DB2 Connect performance tests
Performance and scalability of a large OLTP workload with DB2 9 for System z on Linux
Executive Summary for the DB2 9 for System z on Linux Tests
Introduction to the DB2 9 for System z on Linux Tests
Environmental Setup for the DB2 9 for System z on Linux Tests
Linux Kernel tunables - I/O scheduler
Database Implementation
Results for the DB2 9 for System z on Linux Tests
Notices for the DB2 9 for System z on Linux Tests
Enterprise Content Management
IBM Enterprise Content Management for Linux on z Systems, Scale-Out Case Study (Part 1): Single ECM Node with XFS and IBM Spectrum Scale 4.2
About this publication
Notational conventions
Introduction
Objectives of this white paper
IBM Enterprise Content Management
IBM FileNet P8 Content Platform Engine
IBM Content Navigator
IBM Spectrum Scale Version 4.2
XFS filesystem
Summary
Description of the SUT used with Part 1
Hardware and software configuration of the SUT
IBM z Systems server
Networking setup
IBM storage subsystem setup
Linux virtual machines
IBM ECM server
IBM HTTP Server
IBM DB2 ECM database server
WAS Deployment Manager
IBM Tivoli Directory Server
Workload generator for ICN
Setting up and tuning the SUT
Setting up z/VM
Setting up the virtual network
Setting up HyperPAV
Setting up the Linux operating system
Setting up the network
Setting the buffer count
Setting up the disk I/O
Using HyperPAV for ECKD DASD
FCP Hardware Data Router support
Linux Device Mapper-Multipathing (DM-MP)
Other Linux operating system adaptions
Tuning the ECM gateway
Maximum number of network clients for IBM HTTP Server
Enterprise Content Management application tuning
Common WebSphere Application Server tuning
Thread Pool WebContainer
Object Request Broker services
Java Database Connectivity connection pools
WebSphere Application Server Java virtual machine
IBM FileNet P8 Content Platform Engine (CPE)
IBM Content Navigator
Enterprise Content Management database server
DB2 workload type
DB2 database configuration
Database indexing
Example of database indexing
Results of Enterprise Content Management tuning
Enterprise Content Management workload
FileNet Advanced File Storage Area
Advanced File Storage Area on an XFS filesystem
Advanced File Storage Area on Spectrum Scale
IBM Spectrum Scale tuning parameters
Linux system clock synchronization
IBM Spectrum Scale cache usage
Setting the maxFilesToCache parameter
Setting the pagepool size
Relation between pagepool size and level of maxFilesToCache
Setting the value of maxStatCache
Memory consideration for IBM Spectrum Scale cache usage
IBM Spectrum Scale filesystem parameters
Setting the value of blocksize
Setting a value for the number of inodes
Single Enterprise Content Management (ECM) node results
Enterprise Content Management user scaling for XFS
Transaction throughput and z/VM total CPU load
Average ICN transaction response times
ECM user scaling for IBM Spectrum Scale single node cluster
Average ICN transaction response times
FileNet file storage area disk I/O
z/VM total CPU load for the ECM system
Multiple ECM node setup with Spectrum Scale 4.2 (Part 2 white paper)
References
Notices
Trademarks
Terms and conditions
IBM Enterprise Content Management for Linux on z Systems, Scale-Out Case Study (Part 2): Multiple ECM Nodes with IBM WebSphere Application Server Cluster and Spectrum Scale 4.2
About this publication
Notational conventions
Introduction
Objectives of this white paper
IBM Enterprise Content Management
IBM FileNet P8 Content Platform Engine
IBM Content Navigator
IBM Spectrum Scale Version 4.2
WAS clusters
Summary
Description of the SUT used with Part 2
Hardware and software configuration of the SUT
IBM z Systems server
IBM storage subsystem setup
Networking setup
Linux virtual machines
IBM ECM servers
Spectrum Scale NSD servers
IBM HTTP Server
IBM DB2 ECM database server
WAS Deployment Manager
IBM Tivoli Directory Server
Workload generator for ICN
Setting up and tuning the SUT
Managing the WAS cluster workload
Web server request routing
Round robin option (the default)
Random option
ECM WAS cluster with Spectrum Scale
Important Spectrum Scale parameters
Spectrum Scale node quorum
Spectrum Scale node designations
Spectrum Scale cluster configurations
Shared Disk (SD)
Network Shared Disk (NSD)
Comparison of SD and NSD
Spectrum Scale network block I/O
Jumbo frames
Results of network block I/O tuning
ECM workload
Scale-out study results
ECM user scaling for Spectrum Scale SD
Transaction throughput and average ICN response time
CPU loads for ECM nodes
Disk I/O for ECM nodes
ECM user scaling for Spectrum Scale NSD
Single ECM node with XFS and Spectrum Scale 4.2 (Part 1 white paper)
References
Notices
Trademarks
Terms and conditions
Linux on System z and IBM FileNet P8 5.1 Setup, Performance, and Scalability
About this publication
Introduction
Summary
System under test (SUT) overview
Hardware and software configuration
IBM System z Enterprise 196 z/VM LPAR setup
IBM storage subsystem setup
Network setup
FileNet P8 Content Engine (CE) and Process Engine (PE) Server
FileNet P8 database server
FileNet P8 Application Engine (AE)
LDAP security server
FileNet P8 Enterprise Manager (FEM)
Client system used as ECM workload driver
Setting up the system under test (SUT)
Setting up z/VM
Virtual networking
HyperPAV
Reorder processing
Setting up Linux
Networking
Disk I/O
Installing Websphere Application Server Version 7
FileNet P8 Content Engine (CE)
WebSphere Application Server Version 7 tuning for FileNet P8 Content Engine (CE)
FileNet P8 Process Engine (PE)
Tuning for the FileNet P8 Process Engine - PE Java Virtual Machine settings
DB2 CE/PE database server
Tuning the DB2 CE/PE database server
LDAP security server
Results
Workload scaling
CE/PE throughput and CPU load
CE average response times
PE average response times
CE/PE vertical scalability
CE/PE throughput and CPU load
CE average response times
PE average response times
Tuning overview
References
Related materials about performance
Solutions and best practices
Archive
Distributions
Red Hat Enterprise Linux
9
9.2
9.1
9.0
8
8.7
8.6
8.5
8.4
8.3
8.2
8.1
8.0
7
7.9
7.8
7.7
7.6
7.5
7.4
7.3
7.2
7.1
7.0
6
6.10
6.9
6.8
6.7
6.6
6.5
6.4
6.3
6.2
6.1
6.0
SUSE Linux Enterprise Server
15
15 SP5
15 SP4
15 SP3
15 SP2
15 SP1
15
12
12 SP5
12 SP4
12 SP3
12 SP2
12 SP1
12
11
11 SP4
11 SP3
11 SP2
11 SP1
11
Ubuntu Server
22.04 LTS
20.04 LTS
18.04 LTS
16.04 LTS
z/VM
Device drivers and features
Linux on Power Systems servers