I generally prefer the “dual” Crypto Express hardware security modules — the ones with 2 HSMs per card. For the IBM Crypto Express8S generation that’s most probably Feature Code 0908. Equip your z16/z17/LinuxONE 4/LinuxONE 5 server with quantity 2 of Feature Code 0908, plus order at least 1 TKE Workstation (highly preferably at least 2, to manage whatever number of servers you have), and then you can run both CCA mode and EP11 mode concurrently on your server — with redundancy (2 HSMs per mode). You’ll need only 2 I/O slots per server to do all that.
————— Timothy Sipples Senior Architect Digital Assets, Industry Solutions, and Cybersecurity IBM Z/LinuxONE, Asia-Pacific [email protected] ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
