
206 IBM Eserver zSeries 990 (z990) Cryptography Implementation
Figure A-2 z/OS BSafe implementation
A.2 Overview of the IBM exploiters
The following applications and programs are calling ICSF services that imply the
use of operational keys encrypted under a Master Key or a Key-Encrypting-Key.
Therefore, they require at least one PCIXCC to be in operation for the z/OS
image.
Access Method Services Cryptographic option
CICS attachment facility
CKDS Conversion program
CSFEUTIL program for CKDS re-encipher, refresh, change master key, and
pass phrase initialization functions
CSFPUTIL program for PKDS activate, cache refresh, re-encipher, and ...