| |
Hex Dec Type/Val Lng Label (dup) Comments
---- ---- --------- ---- -------------- --------
0000 0 Structure IPARM IPL parameters
0000 0 Character 32 IPARMS IPL parameters
0020 32 Bitstring 1 * (4) Reserved for Future IBM Use
0024 36 Address 4 IPAEPARM Pointer to extended IPL parm area
0028 40 Bitstring 6 IPADATE Module date/time (YYMMDDHHMMSS)
002E 46 Bitstring 1 IPAINITL Save for SYSINITL field
002F 47 Bitstring 1 IPARFIFL Flag bits (also in HCPIPARX)
1... .... IPACRTST X'80' IPACRTST Certificate store
facilty is available
0030 48 Bitstring 1 * (4) reserved for future use Note:
This word does not survive a
bounce (it contains HCPLOD's
base).
0034 52 Signed 4 IPAOFFST Offset to parm disk
0038 56 Character 8 IPANAME Name of CP module
00000040 IPASIZEB (*-IPARM) Size in bytes
00000008 IPASIZED (*-IPARM+7)/8 Size in d-words
Function : IPAX maps the extended IPL Parameter area
registers 0 through 15 to CP when it is loaded
from a module.
Located by : Created in HCPSAL's and HCPBOU's work page.
- IPAEPARM at entry to HCPLODNC and saved at
HCPLODPM thereafter.
Created by : HCPSAL, HCPBOU
Deleted by : N/A
GENERAL CONSIDERATIONS
Only compatible changes should be made to DSECTs in
HCPIPARM because these data areas are passed from SAPL
or HCPBOU and they may be at different releases than
what the running CP is.
Hex Dec Type/Val Lng Label (dup) Comments
---- ---- --------- ---- -------------- --------
0000 0 Structure IPAX IPL parameters
0000 0 Character 240 IPAXIPRM IPL Parameter buffer
1111 .... IPAXIPRL 240 IPAXIPRL Length of IPL
Parameter buffer
00F0 240 Address 4 IPAXPSIB Pointer to PSIBK. Zero if SAPL.
00F4 244 Signed 4 IPAXDEVS IPL Device Subchannel ID. If
IPL'ed from FCP, this is FCP
Device SubChannel ID
00F8 248 Signed 4 IPAXDEVN (0) IPL Device number
00F8 248 Bitstring 1 * (2) Device number high-order
00FA 250 Bitstring 2 IPAXDEVA IPL Device Number low-order If
IPL'ed from FCP, this is FCP
Device Number.
00FC 252 Bitstring 8 IPAXWWPN WWPN if IPL'ed from FCP Device
0104 260 Bitstring 8 IPAXLUN LUN if IPL'ed from FCP Device
010C 268 Address 4 IPAXSECD Ptr to first IPASECD (SAPL)
0110 272 Address 4 IPAXSEC2 Ptr to second IPASECD (CPLOAD)
0114 276 Bitstring 2 IPAXVERS IPAX version number
0116 278 Bitstring 2 IPAXLEN IPAX length in bytes
0118 280 Character 32 IPAXRSVD Reserved for IBM use
Notes : If IPL from FCP, IPL Parameter PDVOL=<rdev> must b
specified and IPL Device (where SAPL is) must =
SYSRES device (where module is) and must = PARM DISK
device (where config file is).
00000138 IPAXSIZB (*-IPAX) Size in bytes
00000027 IPAXSIZD (*-IPAX+7)/8 Size in d-words
Function : IPASECD maps the security data that is needed
for a secure IPL of CP and to satisfy a
security audit.
Located by : Created in HCPSAL's and HCPBOU's work page.
- IPAXSECD at entry to HCPLODNC and saved at
storage pointed to by HCPSYSIS.
Created by : HCPSAL, HCPBOU
Deleted by : N/A
GENERAL CONSIDERATIONS
Only compatible changes should be made to DSECTs in
HCPIPARM because these data areas are passed from SAPL
or HCPBOU and they may be at different releases than
what the running CP is. This DSECT has a version
number which can possibly be used to handle changes
to the DSECT in the future if care is taken.
Hex Dec Type/Val Lng Label (dup) Comments
---- ---- --------- ---- -------------- --------
0000 0 Structure IPASECD IPL parameters
0000 0 Character 8 IPASEYEC Eye catcher: 'IPASECD '
0008 8 Bitstring 2 IPASVRSN Version number
.... ...1 IPASVERS 1 IPASVERS Current version number
000A 10 Bitstring 2 IPASLENG Length of IPASECD (bytes)
000C 12 Bitstring 1 IPASFLG1 Flag byte
1... .... IPASIPL X'80' IPASIPL This was a secure
IPL
.1.. .... IPASIGND x'40' IPASIGND Loaded object was
signed
000D 13 Bitstring 1 IPASDCF IPL Device Component Flags
1... .... IPASSC X'80' IPASSC Component is signed
.1.. .... IPASCSV X'40' IPASCSV Component Signature
Verified
000E 14 Bitstring 2 IPASCNDX Matching certificate index
0010 16 Bitstring 4 IPASCEI Component Error Indicators
0014 20 Bitstring 4 * Reserved
0018 24 Character 8 IPASCREA Name of IPASECD block creator
(SAPL, HCPBOU, or CPNUC)
0020 32 Character 16 IPASLDTM Date/time of loaded part in
printable EBCDIC format
(YYMMDDHHMMSS)
0030 48 Bitstring 6 IPASCRVR Version of IPASECD creator
0036 54 Bitstring 6 * Reserved
003C 60 Bitstring 4 IPASTKN Cert store token
0040 64 Character 8 IPASLDED Name of what was loaded (SAPL or
cpload module)
0048 72 Signed 8 IPASTODV TOD when verification was done
0050 80 Character 64 IPASCRTNM Name of certificate used for
verification
0090 144 Signed 8 IPASCRTVTM Cert validity start (first 8
bytes of STCKE TOD format)
0098 152 Signed 8 IPASCRTXTM Cert validity expiration (first 8
bytes of STCKE TOD format)
00A0 160 Character 16 IPASMSGS (0) Room for 4 message identifiers of
MSmmmmnn form from HCPMXRBK to
pass to the cpload module to
display during initialization
00A0 160 Signed 4 IPASMSG1 First message to display by CP
00A4 164 Signed 4 IPASMSG2 Second message to display
00A8 168 Signed 4 IPASMSG3 Third message to display
00AC 172 Signed 4 IPASMSG4 Fourth message to display
00B0 176 Bitstring 4 IPASRCS (0) Room for four reason codes
related to IPASMSGS items.
00B0 176 Bitstring 1 IPASRC1 Reason Code for IPASMSG1
00B1 177 Bitstring 1 IPASRC2 Reason Code for IPASMSG2
00B2 178 Bitstring 1 IPASRC3 Reason Code for IPASMSG3
00B3 179 Bitstring 1 IPASRC4 Reason Code for IPASMSG4
00B4 180 Character 4 IPAS8525RC Reason code for msg 8525
00B8 184 Signed 2 IPASHCDSP Displacement from start of
IPASECD to the hash value
calculated during IPL
00BA 186 Signed 2 IPASHCLEN Length of calculated hash
00BC 188 Signed 2 IPASHSDSP Displacement from start of
IPASECD to the hash value used
for signature creation and
obtained from the module
00BE 190 Signed 2 IPASHSLEN Length of the hash value used for
signature creation
00C0 192 Signed 2 IPASVCHDS Displacement from start of the
IPASECD to the VC hash from the
VC extract of the certificate
used for verification
00C2 194 Signed 2 IPASVCHLN Length of the VC hash from the VC
extract of the certificate used
for verification
00C4 196 Signed 2 IPASMEDSP Displacement from start of
IPASECD to the metadata from the
cpload module
00C6 198 Signed 2 IPASMELEN Length of the metadata from the
cpload module
00C8 200 Bitstring 1 IPASHSTYP Hash type
00000001 IPASHST1 1 IPASHST1 SHA2-256 hash type
code from certificate store
architecture Same codes as those
defined for IPASHSTYP
00C9 201 Bitstring 1 IPASVCHT VC Hash type
00CA 202 Bitstring 2 * Reserved for IBM use
00CC 204 Signed 2 IPASMETSD Displacement from start of
IPASECD to the metadata from the
signing server
00CE 206 Signed 2 IPASMETSL Length of the metadata from the
signing server
00D0 208 Signed 2 IPASRVXC Remaining verification extract
count (for debug purposes if
HCPBOS can't get all of the
extracts in one diagnose)
00D2 210 Character 50 * Reserved for IBM use
Below here are fields whose lengths might not always be
the same. Therefore any fields defined below this
point should be accessed using their displacement
within the IPASECD and length which are available in
fixed location fields above. The hash values are all
hardcoded as 32 bytes because today the only hash
algorithm allowed in the architecture is SHA2-256.
0104 260 Character 32 IPASHSHC HASH used for verification and is
calculated during the IPL
0124 292 Character 32 IPASHSHS HASH passed in the module and is
the one used to create the
signature
0144 324 Character 32 IPASVCHS VC Hash from the VC extract entry
of the certificate used for
verification
0164 356 Character 512 IPASMETA PLace for the CPSIGN metadata
record read in from the cpload
module
0364 868 Character 512 IPASGNMET PLace for Signing Server metadata
rec read in from the cpload
module
00000564 IPASECDB (*-IPASECD) Size in bytes
000000AD IPASECDD (*-IPASECD+7)/8 Size in d-words
Function : IPAMETS maps METadata from Signing server
Located by : Created by the signing server when the salipl
$EXTRACT or cpload hash is signed and passed
back with the generated signature.
- Pointed to by IPASMETSD field in IPASECD.
Created by : Signing server, HCPSAL, HCPBOU.
Deleted by : N/A
GENERAL CONSIDERATIONS
Only compatible changes should be made to DSECTs in
HCPIPARM because these data areas are passed from SAPL
or HCPBOU and they may be at different releases than
what the running CP is. This DSECT has a version
number which can possibly be used to handle changes
to the DSECT in the future if care is taken.
Hex Dec Type/Val Lng Label (dup) Comments
---- ---- --------- ---- -------------- --------
0000 0 Structure IPAMETS IPL parameters
0000 0 Character 8 IPAMEYEC Eye catcher: 'IPAMETS '
0008 8 Character 8 IPAMVRSN Version number CL8'1.1.0.0 '
Current version number
0010 16 Character 8 IPAMLENG Length of IPAMETS (bytes in hex)
CL8'0000000 ' Current length
0018 24 Character 10 * Reserved for IBM use
0022 34 Character 6 IPAMZNID Time zone of IPAMSDAT sample
data: "GMT "
0028 40 Character 20 IPAMSDAT Signature timestamp sample data:
"20xx-12-12 22:49:35 "
003C 60 Character 20 IPAMHALG Hash Algorithm sample data:
"SHA2-256 "
0050 80 Character 32 IPAMSALG Signature Algorithm sample data:
"ECDSA - NIST Curve P521 " | + .1
.+ .2 .+ .3 .+ .4
0070 112 Character 72 IPAMHASH Module hash sample data:
"4A8AA33D 54968872 754AEC57
12E6B722 " "60D32406 D460F20B
21033252 9921D4AE "
00B8 184 Character 4 IPAMSEP1 Field separator sample data:
">>> "
00BC 188 Character 72 IPAMFING Certificate Fingerprint sample
data: "4A8AA33D 54968872 754AEC57
12E6B722 " "60D32406 D460F20B
21033252 9921D4AE "
0104 260 Character 4 IPAMSEP2 Field separator sample data:
">>> "
0108 264 Character 220 * Reserved
000001E4 IPAMETSB (*-IPAMETS) Size in bytes
0000003D IPAMETSD (*-IPAMETS+7)/8 Size in d-words
| |