Enterprise Key Management Foundation — Web Edition features

A central repository for keys

How to manage keys

All keys are stored in a central repository with metadata such as activation dates and usage. By storing all key material in this central repository, backup can be easily achieved by including the database in existing backup procedures. This facilitates easy recovery if keys are lost.

Security-rich key generation

Learn about IBM CryptoCards

Key generation takes place within IBM FIPS 140-2 level 4 certified CryptoExpress card on IBM Z for hardware generated keys.

Dual control

Enterprise Key Management Foundation – Web Edition roles can be configured to require that two or more persons must be involved to generate, activate, and distribute keys, thus providing dual control for all operations.

Data set dashboard

A data set dashboard function providing an overview of data sets that are encryptable, already encrypted, or not encryptable. Various search options on this dashboard make it easy to get an overview of the encryption status on an IBM Z server.

Enhanced workflow

By employing automated, semiautomated, and bulk key management processes, workflow can be improved to enable your organization to effectively manage high key volumes.

Role-based access control

The Enterprise Key Management Foundation-Web Edition access control system is role-based and controls the access to functions and keys. The security administrator can define functions and keys that are available for each role and assign users to these roles.

Every important activity is logged in an IBM Db2 table and in z/OS® System Management Facility, if available.

Cloud connectivity

Support for multi-cloud key management, so you can Bring Your Own Key (BYOK) to IBM Cloud Key Protect, AWS KMS, and Microsoft Azure Vault.

External RESTful API

Easily connect and manage keys using an external RESTful API.

Technical details

Software requirements

  • z/OS 2.3 or higher

Hardware requirements

One of the following IBM servers:

  • z15™ (all models)
  • z14® (all models)

Gain agility and flexibility

IBM flexible payment plans help align infrastructure investments with workload needs.