Cryptographic hardware features
This topic describes the cryptographic hardware features available. Information on adding and removing cryptographic coprocessors can be found in z/OS Cryptographic Services ICSF Administrator's Guide.
Crypto Express8 adapter (CEX8C, CEX8P, or CEX8A)
The Crypto Express8 adapter is an asynchronous cryptographic coprocessor or accelerator. The
adapter contains one cryptographic engine that can be configured as a coprocessor (CEX8C for CCA and
CEX8P for PKCS #11) or as an accelerator (CEX8A). It is available on IBM z16
and
IBM z17
.
Crypto Express7 adapter (CEX7C, CEX7P, or CEX7A)
The Crypto Express7 adapter is an asynchronous cryptographic coprocessor or accelerator. The
adapter contains one cryptographic engine that can be configured as a coprocessor (CEX7C for CCA and
CEX7P for PKCS #11) or as an accelerator (CEX7A). One feature may include one or two adapters,
depending on the feature code. It is available on IBM z15, IBM z16,
and IBM
z17
.
Crypto Express6 adapter (CEX6C, CEX6P, or CEX6A)
The Crypto Express6 adapter is an asynchronous cryptographic coprocessor or accelerator. The adapter contains one cryptographic engine that can be configured as a coprocessor (CEX6C for CCA and CEX6P for PKCS #11) or as an accelerator (CEX6A). It is available on IBM z14, IBM z15, and IBM z16.
Crypto Express5 adapter (CEX5C, CEX5P, or CEX5A)
The Crypto Express5 adapter is an asynchronous cryptographic coprocessor or accelerator. The adapter contains one cryptographic engine that can be configured as a coprocessor (CEX5C for CCA and CEX5P for PKCS #11) or as an accelerator (CEX5A). It is available on IBM z14 and IBM z15.
CP Assist for Cryptographic Functions (CPACF)
CPACF is a set of cryptographic instructions available on all CPs. Use of the CPACF instructions provides improved performance. The SHA-1, SHA-2, and SHA-3 algorithms are always available on the servers where the algorithm is supported. Additional algorithms are available with the appropriate enablement. For more information, see Server hardware.
CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement, feature 3863, provides for clear key AES, DES, and TDES instructions. On IBM z15 and later systems, this feature also includes ECC algorithm for P-256, P-384, P-521, Ed25519, and Ed448.