ICSF controls access to cryptographic services through CSFSERV Class. Identity Token Support employs the following ICSF cryptographic services:
- CSFPTRL Token or Object find
- CSFPTRC Token or Object creation
- CSFPGSK Generate secret key
- CSFPTRD Token or Object deletion
- CSFOWH One-Way Hash, Sign or Verify
The security officer role described in the CRYPTOZ section must have the following permissions to these CSFSERV class profiles:
- CSF1TRL (read)
- CSF1TRC (read)
- CSF1TRD (read)
- CSF1GSK (read)
The user role must have the following permissions to CSFSERV class profiles:
- CSF1TRL (read)
- CSFOWH (read)
If one of these CSFSERV class profiles does not exist, permission will be granted in its absence.