UKO does not "replace" the role of the z/OS HSM, nor does it directly manage the hardware master key present inside an HSM as ICSF/TKE does. The HSM root master key (the one that actually encrypts the keys) remains managed inside the HSM and is initialized through traditional procedures (e.g., key ceremony). UKO is not an HSM, but a key orchestration/management layer that can use underlying HSMs to generate and physically protect keys.
------------------------------
Luigi Perrone
------------------------------
Original Message:
Sent: Wed March 04, 2026 02:13 AM
From: Juergen Klaus
Subject: Pervasive Encryption - Master Key Management
Hi,
We use ICSF/TKE/smart cards for master key mgmt and use UKO for PE. In my opinion UKO is not able to manage master keys.
regards Jurgen
------------------------------
Juergen Klaus
------------------------------
Original Message:
Sent: Mon February 09, 2026 04:11 AM
From: Søren Peen
Subject: Pervasive Encryption - Master Key Management
Hello Kazimierz,
I'm not a PE user, but I'd like to inject the option of using the IBM Unified Key Orchestrator. PE is one of the many use-cases supported by this system which provides centralized management and strong backup/recovery options.
https://www.ibm.com/products/unified-key-orchestrator-for-zos
Best regards,
Soren Peen
------------------------------
Søren Peen