Difference between revisions of "E-Business Server:Cannot disable USEICSF"

From SDS
Jump to navigation Jump to search
 
(12 intermediate revisions by the same user not shown)
Line 1: Line 1:
==Cannot disable USEICSF==
+
 
 +
 
 +
 
 +
 
 +
 
 +
== Cannot disable USEICSF ==
  
 
'''Technical Articles ID: SDSKB2'''
 
'''Technical Articles ID: SDSKB2'''
Line 5: Line 10:
  
 
'''Environment'''  
 
'''Environment'''  
E-Business Server 7.xIBM z/OS
+
E-Business Server 7.x<br />
 +
IBM z/OS<br />
 +
IBM USS<br />
  
IBM USS
 
  
 
'''Problem'''
 
'''Problem'''
 +
 
Integrated Cryptographic Service Facility (ICSF) is used even after&nbsp;USEICSF=NO is coded in the config file.
 
Integrated Cryptographic Service Facility (ICSF) is used even after&nbsp;USEICSF=NO is coded in the config file.
  
 +
NOTE: You can use ICSF only if it is available on your computer.
  
NOTE: You can use ICSF only if it is available on your computer.
 
  
 
'''Solution'''
 
'''Solution'''
This issue is being evaluated for consideration in a future release or patched version of the product and an internal product issue has been opened. If this issue significantly impacts your business operations, contact SDS support.
 
 
Note that USEICSF =ON / OFF will still determine whether or not entropy is automatically generated for key creation (USEICSF = ON will turn on automatic entropy generation).
 
  
This article will be updated as newer information becomes available.
+
Upgrade to 7.7.0 or higher.  USEICSF is deprecated as of release 7.7.0, and is replaced by ICSFENCRYPT for data encryption and ICSFRANDOM for random number generation.  The default action is to enable both.
  
'''Workaround'''
+
Note that prior to 7.7, USEICSF =ON / OFF was used to determine whether entropy is automatically generated for key creation AND the use of ICSF for 3DES data encryption. The latter function should have been disabled by USEICSF = NO, but it was not.  In 7.7 the two features are controlled separately, and the controls work for both.
Do not start ICSF or do not use 3DES cipher.
 

Latest revision as of 10:44, 21 October 2019



Cannot disable USEICSF

Technical Articles ID: SDSKB2


Environment E-Business Server 7.x
IBM z/OS
IBM USS


Problem

Integrated Cryptographic Service Facility (ICSF) is used even after USEICSF=NO is coded in the config file.

NOTE: You can use ICSF only if it is available on your computer.


Solution

Upgrade to 7.7.0 or higher. USEICSF is deprecated as of release 7.7.0, and is replaced by ICSFENCRYPT for data encryption and ICSFRANDOM for random number generation. The default action is to enable both.

Note that prior to 7.7, USEICSF =ON / OFF was used to determine whether entropy is automatically generated for key creation AND the use of ICSF for 3DES data encryption. The latter function should have been disabled by USEICSF = NO, but it was not. In 7.7 the two features are controlled separately, and the controls work for both.