This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
aix:vios_release [2021/01/01 21:24] 127.0.0.1 external edit |
aix:vios_release [2024/09/13 15:14] (current) manu |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== PowerVM / VIOS Release NOTE ====== | ====== PowerVM / VIOS Release NOTE ====== | ||
+ | |||
+ | ===== PowerVM v4.1 ===== | ||
+ | |||
+ | AIX 7.3TL2 Benefits for VIOS 4.1 supported on Power 8, 9 and 10 | ||
+ | |||
+ | **Performance** | ||
+ | * Enhanced fork/exec performance | ||
+ | * Power10 optimized data movement (e.g.memcpy, memzero) | ||
+ | * Network and storage stack performance improvements | ||
+ | * HW GZIP for SSH/SCP, dump, and pigz | ||
+ | |||
+ | **Optimized Security** | ||
+ | * AIX program updates for OpenSSL 1.1 or later | ||
+ | * AIX audit check performance | ||
+ | * Security aligned install defaults for networking components | ||
+ | * SSHA-256 password algorithm | ||
+ | * Out of the box long password support (up to 255 chars) | ||
+ | * LVM Encryption option for VIOS rootvg and dump devices | ||
+ | |||
+ | **Security features** | ||
+ | * Supports Trusted Execution, Trusted Update and Secure Boot. | ||
+ | * VIOS boot is made more secure (Secure Boot) and only administrator allowed programs and Kernel Extensions can run with the Trusted Execution feature. This protects system from malicious software & trojans. | ||
+ | * Trusted Update feature ensures that only images that are digitally signed by IBM are allowed to update the existing filesets on the system. | ||
+ | * Default passwords are stronger with the SHA-256 algorithm and also support out of the box long passwords with the maximum of 255 characters. | ||
+ | * Physical volumes that uses the SCSI protocol can be encrypted with hdcryptmgr command (under oem_setup_env), using data encryption key. | ||
+ | * Data protection is enhanced with LVM encryption for rootvg and dump devices. | ||
+ | * Services that are not secure like rexec, rsh are removed. Telnet / ftp services are disabled. If required, users can enable telnet / ftp services. | ||
+ | * ksh93 is used as the default shell in VIOS commands and scripts | ||
+ | |||
+ | **Enhanced Availability** | ||
+ | * Enhanced LLDP reporting | ||
+ | * Enhanced MPIO (faster FC failover, FPIN traffic optimization) | ||
+ | * DLPAR performance for CPU and RAM changes | ||
+ | * Reduced boot time | ||
+ | * Enhanced concurrent change management | ||
+ | |||
+ | **Automation and Modernization** | ||
+ | * Python bundled for Ansible readiness | ||
+ | * Bash | ||
+ | |||
+ | ===== PowerVM v3.1 ===== | ||
BM’s PowerVM virtualization software has been at the AIX 6.1 level for many years. On November 9, 2018, IBM made PowerVM 3.1 available and this level has a base of AIX 7.2 TL3. PowerVM 3.1 is a major update that includes an updated hypervisor, a new VIO server version and a new NovaLink agent. It includes significant improvements in performance, resilience, security and I/O. | BM’s PowerVM virtualization software has been at the AIX 6.1 level for many years. On November 9, 2018, IBM made PowerVM 3.1 available and this level has a base of AIX 7.2 TL3. PowerVM 3.1 is a major update that includes an updated hypervisor, a new VIO server version and a new NovaLink agent. It includes significant improvements in performance, resilience, security and I/O. |