IBM Support

PowerVM VIOS Expansion Pack Software

How To


Summary

This document provides information about how to obtain the PowerVM Virtual I/O Server (VIOS) Expansion Pack and the software included. Such software may be required in environments that need:
- Secure authentication integration (Kerberos / LDAP)
- Hardened network management (secure SNMP)
- Centralized backup using TSM
- Compliance with enterprise security policies

Objective

The VIOS Expansion Pack enhances VIOS by delivering additional VIOS security functions. It is designed for environments that need centralized authentication, secure management protocols, or IBM backup/TSM integration.  

The VIOS Expansion Pack includes the following software.

Kerberos

Kerberos Authentication provides centralized, secure authentication using password and key‑based credentials.
Useful for organizations standardizing authentication across AIX and PowerVM infrastructures.

Configuring a Kerberos client on the Virtual I/O Server
You can configure a Kerberos client on the Virtual I/O Server to enhance security in communications across the internet.

Secure SNMP

Enables encrypted and authenticated SNMP communications.  This protects against unauthorized access to VIOS monitoring interfaces.  For more details, see SNMP on PowerVM VIOS.

Secure LDAP

Allows VIOS to use LDAP as a directory service for centralized user account management.

Tivoli Storage Manager (TSM) Client + GSKit8

Includes TSM client packages and necessary IBM GSKit8 cryptographic libraries.  It enables secure, centralized backup of VIOS data.

Rsyslog

Utility used to forward log messages in an IP network.

Software updates in VIOS Version V4 - 4.1.2.00 Release Notes 

   - The Bind.rte fileset is added to the 12/2025 VIOS V4 Expansion Pack

 

Environment

PowerVM VIOS V3 and V4

Steps

VIOS Expansion Pack is available for download in the Entitled Systems Support (ESS) website.  Software Downloads enables you to download all your entitled software based on authorized customer numbers.

  • Delivered as downloadable *.tar.gz image
  • Offered alongside standard VIOS installation media
  • Requires IBM ID and entitlement tied to customer numbers

 

Pre-Requisites

  1. You need an IBM ID or user id registered.  Click here for details.
  2. You need to be registered for one or more customer numbers in order to see your entitled software.
  3. For questions or problems related to ESS, contact ESS Support for your country or region and be ready to provide your customer number, the machine type, model, and serial number for which the VIOS software is needed.

I Already Have a User ID on IBM Registration

1. Log in to ESS

2. Click My Entitled Software.
 
3. Click Software Downloads.

A page is displayed with 3 different ways to find your product: By category (default), By machine, or By product.

4. In the By category (default) tab, click on the magnifying glass icon.  A list of products is presented, which defaults to your Entitled products.
 
5.  In the Search box, type PowerVM to filter the list and select the desired VIOS Expansion Pack version, PowerVM V4 or PowerVM Enterprise Edition V3:
  1. ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz
  2. ESD-Virtual_I_O_Server_v4_Expansion_Pack_072025_LCD8292603.tar.gz
  3. VIO_v3.1_Expansion_Pack_072025_LCD8250510.tar.gz
 
6. Click Continue 
     > Select the package, such as
         2284: PowerVM V4 Expansion Pack 
       Virtual I/O Server V4 Expansion Pack (12/2025)
     > Click Continue
 
7. Click I agree to accept Terms and conditions and follow the rest of the prompts.
 
 

VIOS V4 Expansion Pack Contents (12/2025)

ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz

-rw-r--r-- 2 4000 4000    4126720 Nov 03 2025 GSKit8.gskcrypt32.ppc.rte
-rw-r--r-- 2 4000 4000    4602880 Nov 03 2025 GSKit8.gskcrypt64.ppc.rte
-rw-r--r-- 2 4000 4000   39394304 Nov 03 2025 GSKit8.gskssl32.ppc.rte
-rw-r--r-- 2 4000 4000   41552896 Nov 03 2025 GSKit8.gskssl64.ppc.rte
-rw-r--r-- 2 4000 4000   14848000 Nov 03 2025 bind.rte             <- New
-rw-r--r-- 2 4000 4000    1465344 Nov 03 2025 idsldap.clt_max_crypto32bit1004
-rw-r--r-- 2 4000 4000    1510400 Nov 03 2025 idsldap.clt_max_crypto64bit1004
-rw-r--r-- 2 4000 4000    4470784 Nov 03 2025 idsldap.cltjava1004
-rw-r--r-- 2 4000 4000   55799808 Nov 03 2025 idsldap.webadmin1004
-rw-r--r-- 2 4000 4000   55067648 Nov 03 2025 idsldap.webadmin_max_crypto1004
-rw-r--r-- 2 4000 4000    5677056 Nov 03 2025 krb5.client
-rw-r--r-- 2 4000 4000    2566144 Nov 03 2025 krb5.doc.en_US
-rw-r--r-- 2 4000 4000     446464 Nov 03 2025 krb5.lic
-rw-r--r-- 2 4000 4000     936960 Nov 03 2025 rsync.rte
-rw-r--r-- 2 4000 4000    8015872 Nov 03 2025 rsyslog.base
-rw-r--r-- 2 4000 4000     438272 Nov 03 2025 rsyslog.license
-rw-r--r-- 2 4000 4000    2789376 Nov 03 2025 snmp.crypto

 

VIOS V4 Expansion Pack Contents (07/2025)

ESD-Virtual_I_O_Server_v4_Expansion_Pack_072025_LCD8292603.tar.gz
 

-rw-r--r-- 2 4000 4000    4126720 Jun 13 2025 GSKit8.gskcrypt32.ppc.rte
-rw-r--r-- 2 4000 4000    4602880 Jun 13 2025 GSKit8.gskcrypt64.ppc.rte
-rw-r--r-- 2 4000 4000   39172096 Jun 13 2025 GSKit8.gskssl32.ppc.rte
-rw-r--r-- 2 4000 4000   41362432 Jun 13 2025 GSKit8.gskssl64.ppc.rte
-rw-r--r-- 2 4000 4000    1370112 Jun 13 2025 idsldap.clt_max_crypto32bit1002
-rw-r--r-- 2 4000 4000    1434624 Jun 13 2025 idsldap.clt_max_crypto64bit1002
-rw-r--r-- 2 4000 4000    1021952 Jun 13 2025 idsldap.cltjava1002
-rw-r--r-- 2 4000 4000   57247744 Jun 13 2025 idsldap.webadmin1002
-rw-r--r-- 2 4000 4000   56514560 Jun 13 2025 idsldap.webadmin_max_crypto1002
-rw-r--r-- 2 4000 4000    5653504 Jun 13 2025 krb5.client
-rw-r--r-- 2 4000 4000    2566144 Jun 13 2025 krb5.doc.en_US
-rw-r--r-- 2 4000 4000     446464 Jun 13 2025 krb5.lic
-rw-r--r-- 2 4000 4000    8020992 Jun 13 2025 rsyslog.base
-rw-r--r-- 2 4000 4000     438272 Jun 13 2025 rsyslog.license
-rw-r--r-- 2 4000 4000    2789376 Jun 13 2025 snmp.crypto

 

VIOS V3 Expansion Pack Contents (07/2025)

VIO_v3.1_Expansion_Pack_072025_LCD8250510.tar.gz

GSKit8.gskcrypt32.ppc.rte
GSKit8.gskcrypt64.ppc.rte
GSKit8.gskssl32.ppc.rte
GSKit8.gskssl64.ppc.rte
idsldap.cltjava100
idsldap.clt_max_crypto32bit100
idsldap.clt_max_crypto64bit100
idsldap.webadmin100
idsldap.webadmin_max_crypto100
krb5.client
krb5.doc.en_US
krb5.lic
rsyslog.base
rsyslog.license
snmp.crypto

 

How to Unpackage the *.tar.gz image
 

1) Create a local directory on the VIOS partition and transfer the *.tar.gz file to it

$ oem_setup_env
# mkdir /home/padmin/vio_exp_pk
Transfer file
# cd vio_exp_pk
# ls
ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz

2) Unpackage the *.tar.gz image using gzip command. Then, extract files from the *.tar archive using tar command, e.g. 

# gzip -d ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar.gz
# tar -xvf ESD-Virtual_I_O_Server_v4_Expansion_Pack_122025_LCD8292604.tar
x .
x ./installp
x ./installp/ppc
x ./installp/ppc/GSKit8.gskcrypt32.ppc.rte, 4126720 bytes, 8060 media blocks.
...snip...
 

Notice the software/filesets will be extracted into ./installp/ppc directory. Change to that directory to list all contents:

# cd installp/ppc
# ls -la
 
 
How to Install a Software Package
 

$ cfgassist
> Install and Update Software
> Install Software
INPUT device/directory for software    [/path_containing_package_to_install] 
SOFTWARE to install                    [Select desired software package to install]

In the following example, the VIOS expansion pack has been unpackaged in /home/padmin/vio_exp_pk/installp/ppc and snmp.crypto software will be installed.
 
$ cfgassist
> Install and Update Software
> Install Software
INPUT device/directory for software     [/home/padmin/vio_exp_pk/installp/ppc
SOFTWARE to install                     [Search for snmp.crypto and select it]

                                                      
                              Install Software
                                                                                                                                                                                    
Type or select values in entry fields.
Press Enter AFTER making all desired changes.
                                         [Entry Fields]
INPUT device/directory for software      /home/padmin/vio_exp_pk/installp/ppc
SOFTWARE to install                      [snmp.crypto ALL @@I:snmp.crypto _all> +

                               COMMAND STATUS
                               
Command: OK stdout: yes stderr: no

Before command completion, additional instructions may appear below.

geninstall -I "a -cgQqwX -J" -Z -d /home/padmin/hammond/vio_exp_pk/072025-411/installp/ppc -f File 2>&1

File:
    I:snmp.crypto                  7.2.0.2
+-----------------------------------------------------------------------------+
                    Pre-installation Verification...
+-----------------------------------------------------------------------------+
Verifying selections...done
Verifying requisites...done
Results...

SUCCESSES
---------
  Filesets listed in this section passed pre-installation verification
  and will be installed.

  Selected Filesets
  -----------------
  snmp.crypto 7.2.0.2                          # 56-bit DES Encrypted SNMPV3 ...
  
<< End of Success Section >>

+-----------------------------------------------------------------------------+
                    BUILDDATE Verification ...
+-----------------------------------------------------------------------------+
Verifying build dates...done
FILESET STATISTICS
------------------
     1  Selected to be installed, of which:
         1  Passed pre-installation verification
   ----
     1  Total to be installed
     
+-----------------------------------------------------------------------------+
                          Installing Software...
+-----------------------------------------------------------------------------+

installp: APPLYING software for:
        snmp.crypto 7.2.0.2
        
. . . . . << Copyright notice for snmp.crypto >> . . . . . . .
 Licensed Materials - Property of IBM

 5765G6200
 Copyright International Business Machines Corp. 2001, 2025.

 All rights reserved.
 US Government Users Restricted Rights - Use, duplication or disclosure
 restricted by GSA ADP Schedule Contract with IBM Corp.
. . . . . << End of copyright notice for snmp.crypto >>. . . .

0513-059 The snmpd Subsystem has been started. Subsystem PID is 8585544.
Finished processing all filesets. (Total time: 8 secs).

+-----------------------------------------------------------------------------+
                                Summaries:
+-----------------------------------------------------------------------------+
Installation Summary
--------------------
Name                         Level         Part           Event      Result
-------------------------------------------------------------------------------
snmp.crypto                  7.2.0.2       USR            APPLY      SUCCESS
snmp.crypto                  7.2.0.2       ROOT           APPLY      SUCCESS

$ lssw|grep -i snmp
  bos.net.tcp.snmp            7.3.3.0     C     F    TCP/IP SNMP Client Application
  bos.net.tcp.snmpd           7.3.3.1     C     F    TCP/IP SNMP Server Application
  snmp.crypto                 7.2.0.2     C     F    56-bit DES Encrypted SNMPV3      <==
  There is no efix data on this system.
 

Verify Installation, e.g.

$ lssw|grep -i snmp

 
NOTE 1
When a VIOS is updated, e.g. from 4.1.1.x to 4.1.2.x, filesets installed from the VIOS Expansion Pack must be updated as well using the latest VIOS Expansion Pack if updates are available in the newer VIOS Expansion pack.
 
NOTE 2

Software installed from the VIOS Expansion Pack must be reinstall after a VIOS is upgraded to a new version, such as from VIOS V3 to V4.

 

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB57","label":"Power"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSPHKW","label":"PowerVM Virtual I\/O Server"},"ARM Category":[{"code":"a8m0z000000CbbjAAC","label":"OTHER-\u003EApproved apps on VIOS"}],"ARM Case Number":"TS021287416","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"3.1.0;3.1.1;3.1.2;3.1.3;3.1.4;4.1.0;4.1.1;4.1.2"}]

Document Information

Modified date:
18 August 2026

UID

ibm17258293