IBM Crypto Education Community

IBM Crypto Education Community

IBM Crypto Education Community

Join the IBM Crypto Education community to explore and understand IBM cryptography technology. This community is operated and maintained by the IBM Crypto Development team.

 View Only
  • 1.  Pervasive Encryption - Master Key Management

    Posted 02/06/26 06:27 AM

    Question for PE users. What Master Key Management method do you use:
    1. Only ICSF
    2. TKE Smart Card
    3. TKE Binary file
    4. TKE Print file/Keyboar
    Each method has advantages and disadvantages. I would like to know your opinions.

    Thanks in advance.



    ------------------------------
    Kazimierz Miklaszewski
    ------------------------------


  • 2.  RE: Pervasive Encryption - Master Key Management

    Posted 02/09/26 08:17 AM

    Hello Kazimierz,

    I'm not a PE user, but I'd like to inject the option of using the IBM Unified Key Orchestrator. PE is one of the many use-cases supported by this system which provides centralized management and strong backup/recovery options.
    https://www.ibm.com/products/unified-key-orchestrator-for-zos

    Best regards,
    Soren Peen



    ------------------------------
    Søren Peen
    ------------------------------



  • 3.  RE: Pervasive Encryption - Master Key Management

    Posted 03/04/26 09:13 AM

    Hi,

    We use ICSF/TKE/smart cards for master key mgmt and use UKO for PE. In my opinion UKO is not able to manage master keys.

    regards Jurgen



    ------------------------------
    Juergen Klaus
    ------------------------------



  • 4.  RE: Pervasive Encryption - Master Key Management

    Posted 03/05/26 08:16 AM

    UKO does not "replace" the role of the z/OS HSM, nor does it directly manage the hardware master key present inside an HSM as ICSF/TKE does. The HSM root master key (the one that actually encrypts the keys) remains managed inside the HSM and is initialized through traditional procedures (e.g., key ceremony). UKO is not an HSM, but a key orchestration/management layer that can use underlying HSMs to generate and physically protect keys.



    ------------------------------
    Luigi Perrone
    ------------------------------