IBM 4767 library
Product documentation for the IBM 4767 is available in PDF format. To view a PDF document, you need the Adobe® (Adobe Systems Incorporated) Reader®. If you don't have the Reader installed, you can download a complimentary copy from Adobe.
The IBM 4767 is available on these platforms:
IBM Z mainframe. The 4767 is available as feature code (FC) 0890 (Crypto Express5S, or CEX5S) on IBM Z mainframes (z14, z13s, and z13 only), either on z/OS® or Linux® on z Systems® operating systems.
- The CEX5S publications for z/OS are not available here.
- On Linux on z Systems, IBM offers a CCA API for the CEX5S and a PKCS #11 (EP11) API to the user.
x64 servers. The 4767 is available as machine type-model 4767-002 on x64 servers on either Microsoft® Windows®, SUSE® Linux Enterprise Server (SLES), or Red Hat® Enterprise Linux® (RHEL) 64-bit operating systems. IBM offers a Common Cryptographic Architecture (CCA) Support Program for the IBM 4767 at no charge to the user.
IBM Power Systems. The 4767 is available as FC EJ32, Customer Card Identification Number 4767 (without blind-swap cassette custom carrier) and as FC EJ33, Customer Card Identification Number 4767 (with blind-swap cassette custom carrier) on IBM POWER8® servers, either on IBM AIX®, IBM i®, or PowerLinux® (RHEL, SLES, or Ubuntu®) operating systems.

HSM 4767 general documentation
These manuals apply to the IBM 4767 PCIe Cryptographic Coprocessor.
IBM 4767 data sheet (PDF, 326 KB)
IBM 4767 PCIe Cryptographic Coprocessor Installation Manual (PDF, 876 KB)
IBM Systems Environmental Notices and User Guide, Z125-5823
IBM Systems Safety Notices, G229-9054
IBM Warranty Information for the 4767-002 and 4765-001 PCle Cryptographic Coprocessors (PDF, 693 KB), SC23-6884
IBM Statement of Limited Warranty, Z125-4753-13
IBM License Agreement for Machine Code (Contains Form Z125-5468-06) (PDF, 4.3 MB)
IBM 4767 CCA Support Program
The CCA Basic Services and Secure Key Solution manuals describe the capabilities of the security application programming interface (API) provided with the CCA Support Program, while the CCA Support Program Installation manual describes how to install CCA. Refer to the Manuals by platform table to select these manuals by platform.
Manuals by platform
IBM 4767 custom programming
Custom Software Developer's Toolkit Guide
This guide describes the tools that enable developers to build applications for the IBM 4767, authenticate programs, and load programs into the IBM 4767.
IBM 4767 PCIe Cryptographic Coprocessor Custom Software Developer's Toolkit Guide (PDF, 1 MB)
Custom Software Interface Reference
This manual describes the function calls that applications running in the IBM 4767 use to obtain services from the coprocessor operating system and from the coprocessor device driver in the host system.
IBM 4767 PCIe Cryptographic Coprocessor Custom Software Interface Reference (PDF, 859 KB)
CCA User Defined Extensions Reference and Guide
This manual describes the user-defined extensions programming environment within the CCA application in the IBM 4767, the method for extending the CCA host API, and the application programming interface reference for these environments.
Interactive Code Analysis Tool (ICAT)
This manual describes the tool that developers use to debug applications running on the IBM 4767.
IBM 4767 PCIe Cryptographic Coprocessor ICAT Getting Started (PDF, 333 KB)
IBM 4767 optional smart cards and readers for Linux users
Smart Card User Guide
This manual describes the IBM Smart Card Utility Program (SCUP) and SCUP-enabled Cryptographic Node Management (CNM) utility.
IBM 4767 PCIe Cryptographic Coprocessor Smart Card User Guide (PDF, 2.9 MB)
IBM 4767 CCA utilities
CCA Utilities User Guide
IBM PCIe Cryptographic Coprocessors, also known as hardware security modules (HSMs), for z/OS and Linux on IBM Z, IBM AIX and IBM i on Power Systems, and SLES, RHEL, and Windows servers on x86 servers.
IBM 4767 PCIe Cryptographic Coprocessor CCA Utilities User Guide (PDF, 519 KB)
IBM 4767 Enterprise PKCS #11 (EP11)
This manual describes the library structure and capabilities of the cryptographic application programming interface (API) provided with the Enterprise PKCS#11 (EP11) Library for Linux on Z.
Related products
The IBM CPACF Enablement crypto feature
The IBM Central Processor Assist for Cryptographic Functions (CPACF) feature, IBM Z feature code 3863, provides hardware acceleration for 290-960 MB/sec bulk encryption rate, AES (128, 192, 256 bit), DES (DEA, TDEA2, TDEA3), SHA-1 (160 bit), and SHA-2 (224, 256, 384, 512 bit).
The IBM Cryptographic Coprocessor Facility (CCF)
The Cryptographic Coprocessor Facility (CCF) is an optional hardware feature that provides high-performance cryptographic capabilities for z/VM®, including DES, Triple-DES, RSA, and various finance-industry-specific cryptographic services. IBM zSeries servers, except the zSeries 990, offer the CCF feature.
Standards and technology
Follow us
Follow us