IBM®
Skip to main content
    Country/region [select]      Terms of use
 
 
   
     Home      Products      Services & industry solutions      Support & downloads      My IBM     
Security
Cryptocards
PCI-X Cryptographic Coprocessor
PCI Cryptographic Accelerator
PCI Cryptographic Coprocessor
Product Summary
Library
Order
Support

IBM PCI Cryptographic Coprocessor

Highlights of Release 2.41 (AIX: 2.4.1.0; Windows 2000/NT: 2.41)

Release 2.41 is available for download for all IBM 4758 Model 002 and 023 customers who use Windows 2000®, Windows NT®, and customers who use AIX with pSeries features #4958 and #4963. Release 2.41 provides additional function and performance for all customers and fixes problems encountered with the earlier releases.

Highlights of the new and additional support for CCA include:

  • New capabilities have been added to the Key Part Import verb permitting improved separation of function between individuals and defense against unauthorized clear-key modification.
  • The rules applying to key-length during import and export of DES keys have been tightened. The old rules can be used provided new access control points are authorized.
  • Host-side key-storage key-caching can now be disabled enabling those who access the same keys from multiple processes to immediately work with updated keys.
  • Support of the IBM 3624 PIN-generation method is added to the Encrypted PIN Generate verb.
  • The Encrypted PIN Verify verb can optionally enforce that verified PINs are four digits in length when using the VISA-PVV PIN calculation method.
  • The PKA Key Token Change verb is modified to give return and reason codes zero when requested to update a public-key-only record.
  • Fixes have been applied to the Diversified Key Generate, Encrypted PIN Generate, Encrypted PIN Verify, Key Token Change, and DES Key Record Create verbs.
  • New device drivers for AIX for 32-bit and 64-bit environments are supplied.
  • Multi-threaded support for multiple Coprocessors on Windows NT and Windows 2000 has been improved.
  • The Cryptographic Node Management (CNM) utility is modified to permit only 1024-bit length keys. You still can write applications to employ keys up to 2048-bit lengths.
  • The diagnostic trace facility has been removed from the host component.

Highlights of the new and additional support for PKCS #11 include:

  • Relative key length restrictions have been added to C_WrapKey when wrapping one secret key with another secret key.
  • New device drivers for AIX for 32-bit and 64-bit environments are supplied.

See Release 2.40 for enhancements in the earlier release.



    About IBM Privacy Contact