How To
Summary
This document provides information about how to obtain the PowerVM Virtual I/O Server (VIOS) Expansion Pack and the software included. Such software may be required in environments that need:
- Secure authentication integration (Kerberos / LDAP)
- Hardened network management (secure SNMP)
- Centralized backup using TSM
- Compliance with enterprise security policies
Objective
The VIOS Expansion Pack enhances VIOS by delivering additional VIOS security functions. It is designed for environments that need centralized authentication, secure management protocols, or IBM backup/TSM integration.
The VIOS Expansion Pack includes the following software.
Kerberos
Kerberos Authentication provides centralized, secure authentication using password and key‑based credentials.
Useful for organizations standardizing authentication across AIX and PowerVM infrastructures.
Configuring a Kerberos client on the Virtual I/O Server
You can configure a Kerberos client on the Virtual I/O Server to enhance security in communications across the internet.
Secure SNMP
Enables encrypted and authenticated SNMP communications. This protects against unauthorized access to VIOS monitoring interfaces. For more details, see SNMP on PowerVM VIOS.
Secure LDAP
Allows VIOS to use LDAP as a directory service for centralized user account management.
Tivoli Storage Manager (TSM) Client + GSKit8
Includes TSM client packages and necessary IBM GSKit8 cryptographic libraries. It enables secure, centralized backup of VIOS data.
Rsyslog
Utility used to forward log messages in an IP network.
Software updates in VIOS Version V4 - 4.1.2.00 Release Notes
- The Bind.rte fileset is added to the 12/2025 VIOS V4 Expansion Pack
Environment
PowerVM VIOS V3 and V4
Steps
VIOS Expansion Pack is available for download in the Entitled Systems Support (ESS) website. Software Downloads enables you to download all your entitled software based on authorized customer numbers.
- Delivered as downloadable *.tar.gz image
- Offered alongside standard VIOS installation media
- Requires IBM ID and entitlement tied to customer numbers
Pre-Requisites
- You need an IBM ID or user id registered. Click here for details.
- You need to be registered for one or more customer numbers in order to see your entitled software.
- For questions or problems related to ESS, contact ESS Support for your country or region and be ready to provide your customer number, the machine type, model, and serial number for which the VIOS software is needed.
I Already Have a User ID on IBM Registration
1. Log in to ESS
A page is displayed with 3 different ways to find your product: By category (default), By machine, or By product.
- ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz
- ESD-Virtual_I_O_Server_v4_Expansion_Pack_072025_LCD8292603.tar.gz
- VIO_v3.1_Expansion_Pack_072025_LCD8250510.tar.gz
VIOS V4 Expansion Pack Contents (12/2025)
ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz
-rw-r--r-- 2 4000 4000 4126720 Nov 03 2025 GSKit8.gskcrypt32.ppc.rte
-rw-r--r-- 2 4000 4000 4602880 Nov 03 2025 GSKit8.gskcrypt64.ppc.rte
-rw-r--r-- 2 4000 4000 39394304 Nov 03 2025 GSKit8.gskssl32.ppc.rte
-rw-r--r-- 2 4000 4000 41552896 Nov 03 2025 GSKit8.gskssl64.ppc.rte
-rw-r--r-- 2 4000 4000 14848000 Nov 03 2025 bind.rte <- New
-rw-r--r-- 2 4000 4000 1465344 Nov 03 2025 idsldap.clt_max_crypto32bit1004
-rw-r--r-- 2 4000 4000 1510400 Nov 03 2025 idsldap.clt_max_crypto64bit1004
-rw-r--r-- 2 4000 4000 4470784 Nov 03 2025 idsldap.cltjava1004
-rw-r--r-- 2 4000 4000 55799808 Nov 03 2025 idsldap.webadmin1004
-rw-r--r-- 2 4000 4000 55067648 Nov 03 2025 idsldap.webadmin_max_crypto1004
-rw-r--r-- 2 4000 4000 5677056 Nov 03 2025 krb5.client
-rw-r--r-- 2 4000 4000 2566144 Nov 03 2025 krb5.doc.en_US
-rw-r--r-- 2 4000 4000 446464 Nov 03 2025 krb5.lic
-rw-r--r-- 2 4000 4000 936960 Nov 03 2025 rsync.rte
-rw-r--r-- 2 4000 4000 8015872 Nov 03 2025 rsyslog.base
-rw-r--r-- 2 4000 4000 438272 Nov 03 2025 rsyslog.license
-rw-r--r-- 2 4000 4000 2789376 Nov 03 2025 snmp.crypto
VIOS V4 Expansion Pack Contents (07/2025)
-rw-r--r-- 2 4000 4000 4126720 Jun 13 2025 GSKit8.gskcrypt32.ppc.rte
-rw-r--r-- 2 4000 4000 4602880 Jun 13 2025 GSKit8.gskcrypt64.ppc.rte
-rw-r--r-- 2 4000 4000 39172096 Jun 13 2025 GSKit8.gskssl32.ppc.rte
-rw-r--r-- 2 4000 4000 41362432 Jun 13 2025 GSKit8.gskssl64.ppc.rte
-rw-r--r-- 2 4000 4000 1370112 Jun 13 2025 idsldap.clt_max_crypto32bit1002
-rw-r--r-- 2 4000 4000 1434624 Jun 13 2025 idsldap.clt_max_crypto64bit1002
-rw-r--r-- 2 4000 4000 1021952 Jun 13 2025 idsldap.cltjava1002
-rw-r--r-- 2 4000 4000 57247744 Jun 13 2025 idsldap.webadmin1002
-rw-r--r-- 2 4000 4000 56514560 Jun 13 2025 idsldap.webadmin_max_crypto1002
-rw-r--r-- 2 4000 4000 5653504 Jun 13 2025 krb5.client
-rw-r--r-- 2 4000 4000 2566144 Jun 13 2025 krb5.doc.en_US
-rw-r--r-- 2 4000 4000 446464 Jun 13 2025 krb5.lic
-rw-r--r-- 2 4000 4000 8020992 Jun 13 2025 rsyslog.base
-rw-r--r-- 2 4000 4000 438272 Jun 13 2025 rsyslog.license
-rw-r--r-- 2 4000 4000 2789376 Jun 13 2025 snmp.crypto
VIOS V3 Expansion Pack Contents (07/2025)
VIO_v3.1_Expansion_Pack_072025_LCD8250510.tar.gz
GSKit8.gskcrypt32.ppc.rte
GSKit8.gskcrypt64.ppc.rte
GSKit8.gskssl32.ppc.rte
GSKit8.gskssl64.ppc.rte
idsldap.cltjava100
idsldap.clt_max_crypto32bit100
idsldap.clt_max_crypto64bit100
idsldap.webadmin100
idsldap.webadmin_max_crypto100
krb5.client
krb5.doc.en_US
krb5.lic
rsyslog.base
rsyslog.license
snmp.crypto
1) Create a local directory on the VIOS partition and transfer the *.tar.gz file to it
$ oem_setup_env
# mkdir /home/padmin/vio_exp_pk
Transfer file
# cd vio_exp_pk
# ls
ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz2) Unpackage the *.tar.gz image using gzip command. Then, extract files from the *.tar archive using tar command, e.g.
# gzip -d ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz
# tar -xvf ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar
x .
x ./installp
x ./installp/ppc
x ./installp/ppc/GSKit8.gskcrypt32.ppc.rte, 4126720 bytes, 8060 media blocks.
...snip...Notice the software/filesets will be extracted into ./installp/ppc directory. Change to that directory to list all contents:
# cd installp/ppc
# ls -la$ cfgassist
> Install and Update Software
> Install Software
INPUT device/directory for software [/path_containing_package_to_install]
SOFTWARE to install [Select desired software package to install]
$ cfgassist
> Install and Update Software
> Install Software
INPUT device/directory for software [/home/padmin/vio_exp_pk/installp/ppc
SOFTWARE to install [Search for snmp.crypto and select it]
Install Software
Type or select values in entry fields.
Press Enter AFTER making all desired changes.
[Entry Fields]
INPUT device/directory for software /home/padmin/vio_exp_pk/installp/ppc
SOFTWARE to install [snmp.crypto ALL @@I:snmp.crypto _all> +
COMMAND STATUS
Command: OK stdout: yes stderr: no
Before command completion, additional instructions may appear below.
geninstall -I "a -cgQqwX -J" -Z -d /home/padmin/hammond/vio_exp_pk/072025-411/installp/ppc -f File 2>&1
File:
I:snmp.crypto 7.2.0.2
+-----------------------------------------------------------------------------+
Pre-installation Verification...
+-----------------------------------------------------------------------------+
Verifying selections...done
Verifying requisites...done
Results...
SUCCESSES
---------
Filesets listed in this section passed pre-installation verification
and will be installed.
Selected Filesets
-----------------
snmp.crypto 7.2.0.2 # 56-bit DES Encrypted SNMPV3 ...
<< End of Success Section >>
+-----------------------------------------------------------------------------+
BUILDDATE Verification ...
+-----------------------------------------------------------------------------+
Verifying build dates...done
FILESET STATISTICS
------------------
1 Selected to be installed, of which:
1 Passed pre-installation verification
----
1 Total to be installed
+-----------------------------------------------------------------------------+
Installing Software...
+-----------------------------------------------------------------------------+
installp: APPLYING software for:
snmp.crypto 7.2.0.2
. . . . . << Copyright notice for snmp.crypto >> . . . . . . .
Licensed Materials - Property of IBM
5765G6200
Copyright International Business Machines Corp. 2001, 2025.
All rights reserved.
US Government Users Restricted Rights - Use, duplication or disclosure
restricted by GSA ADP Schedule Contract with IBM Corp.
. . . . . << End of copyright notice for snmp.crypto >>. . . .
0513-059 The snmpd Subsystem has been started. Subsystem PID is 8585544.
Finished processing all filesets. (Total time: 8 secs).
+-----------------------------------------------------------------------------+
Summaries:
+-----------------------------------------------------------------------------+
Installation Summary
--------------------
Name Level Part Event Result
-------------------------------------------------------------------------------
snmp.crypto 7.2.0.2 USR APPLY SUCCESS
snmp.crypto 7.2.0.2 ROOT APPLY SUCCESS
$ lssw|grep -i snmp
bos.net.tcp.snmp 7.3.3.0 C F TCP/IP SNMP Client Application
bos.net.tcp.snmpd 7.3.3.1 C F TCP/IP SNMP Server Application
snmp.crypto 7.2.0.2 C F 56-bit DES Encrypted SNMPV3 <==
There is no efix data on this system.Verify Installation, e.g.
$ lssw|grep -i snmp
Software installed from the VIOS Expansion Pack must be reinstall after a VIOS is upgraded to a new version, such as from VIOS V3 to V4.
Related Information
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
18 August 2026
UID
ibm17258293