overview pictogram of a lock and key

z/OS Trusted Key Entry Workstation content solution

The z/OS® Trusted Key Entry Workstation allows you to manage IBM Z® host cryptographic modules running in Common Cryptographic Architecture (CCA) or IBM Enterprise PKCS#11 (EP11) mode, using compliant-level hardware-based key management techniques. IBM Z host crypto modules must be managed according to strict policies, which are influenced by various legal, regulator, and compliance requirements. In many cases, the final policies must include dual control management and hardware-based master key part protection to pass internal and external security audits.

If you are new to the crypto world or having trouble defining your policy, no problem. TKE provides a set of wizards that help you define and implement a set of security policies for managing your TKE appliance and your host crypto modules.

Big Picture: z/OS Trusted Key Entry Workstation

pictogram for step 1 - install

1. Install the TKE console and ensure that it is up and running.

pictogram for step 2 - establish security policies

2. Establish the security policies for your system.

pictogram for step 3 - run the smart card wizard

3. Run the TKE Smart Card wizard to create all the smart cards needed by the other TKE wizards.

pictogram for step 4 - run the workstation profile wizard

4. Run the TKE Workstation Logon Profile Wizard to manage access to the TKE workstation.

pictogram for step 5 - run security policy wizards

5. Run the other TKE security policy wizards to set up administrator access to manage host crypto modules.

How to get started with z/OS Trusted Key Entry Workstation

Technical resources for z/OS Trusted Key Entry Workstation

Initialize your new Trusted Key Entry (TKE)

Trusted Key Entry (TKE) CCA Playlist

IBM TKE easy way to migrate or clone a TKE workstation

Overview of the IBM TKE host crypto module migration feature

Using Trusted Key Entry (TKE) to initialize smart cards

Create TKE local crypto adapter profiles using the TKE workstation logon profile wizard

What's new

June 25, 2021

The Big Picture section has been modified for accessibility.

June 18, 2021

The link to a Hot Topics article on the Other resources tab in the Technical resources section was updated to find the article in the archives of the new IBM Z Hot Topics website.