Cryptographic hardware features

This topic describes the cryptographic hardware features available. Information on adding and removing cryptographic coprocessors can be found in z/OS Cryptographic Services ICSF Administrator's Guide.

Crypto Express8 adapter (CEX8C, CEX8P, or CEX8A)

The Crypto Express8 adapter is an asynchronous cryptographic coprocessor or accelerator. The adapter contains one cryptographic engine that can be configured as a coprocessor (CEX8C for CCA and CEX8P for PKCS #11) or as an accelerator (CEX8A). It is available on IBM z16 Start of changeand IBM z17End of change.

Crypto Express7 adapter (CEX7C, CEX7P, or CEX7A)

The Crypto Express7 adapter is an asynchronous cryptographic coprocessor or accelerator. The adapter contains one cryptographic engine that can be configured as a coprocessor (CEX7C for CCA and CEX7P for PKCS #11) or as an accelerator (CEX7A). One feature may include one or two adapters, depending on the feature code. It is available on IBM z15, IBM z16, Start of changeand IBM z17End of change.

Crypto Express6 adapter (CEX6C, CEX6P, or CEX6A)

The Crypto Express6 adapter is an asynchronous cryptographic coprocessor or accelerator. The adapter contains one cryptographic engine that can be configured as a coprocessor (CEX6C for CCA and CEX6P for PKCS #11) or as an accelerator (CEX6A). It is available on IBM z14, IBM z15, and IBM z16.

Crypto Express5 adapter (CEX5C, CEX5P, or CEX5A)

The Crypto Express5 adapter is an asynchronous cryptographic coprocessor or accelerator. The adapter contains one cryptographic engine that can be configured as a coprocessor (CEX5C for CCA and CEX5P for PKCS #11) or as an accelerator (CEX5A). It is available on IBM z14 and IBM z15.

CP Assist for Cryptographic Functions (CPACF)

CPACF is a set of cryptographic instructions available on all CPs. Use of the CPACF instructions provides improved performance. The SHA-1, SHA-2, and SHA-3 algorithms are always available on the servers where the algorithm is supported. Additional algorithms are available with the appropriate enablement. For more information, see Server hardware.

CP Assist for Cryptographic Functions (CPACF) DES/TDES Enablement, feature 3863, provides for clear key AES, DES, and TDES instructions. On IBM z15 and later systems, this feature also includes ECC algorithm for P-256, P-384, P-521, Ed25519, and Ed448.