User Guide
DDOC0099-000-AH
DTS1 CSfC
8 - 1
System Configuration
© 2020 Curtiss-Wright Defense Solutions
Revision 1.0
System Configuration
The commands below are used to configure the crypto module, DTS1, and associated RMC
module.
8.1
Crypto Module
The cmlogin command allows for initialization of / logging into the Hardware Encryption (HWE)
crypto module. For status information, issue cmlogin without options. Refer to paragraph 12.3.4
for detailed information about initializing /logging into the HWE crypto module.
The cmkey command allows for management of keys on the HWE crypto module. For status
information, issue cmkey without options. Refer to paragraph 12.3.3
information about configuring the crypto module.
8.1.1
Initialize / Log In
NOTE
[
username
]
and
[
password
]
are selected and entered by the user.
cmlogin -u
[username]
-p
[password]
-I
........................Initialize HWE crypto module.
cmlogin -u
[username]
-p
[password]
................................Log into HWE crypto module.
cmlogin -M
..................................................................................Authorize HWE crypto module
password.
8.1.2
Key Load / Unload
cmkey --auto
.........................Auto-load the saved key for RMC module.
cmkey --load
.........................Load a saved key for RMC module.
cmkey --unload
.....................Unload/zeroize key from RMC module.
8.1.3
Key Removal / Zeroize
cmkey --del
...........................Delete/zeroize a saved key.
cmkey -Z
..................................Zeroize crypto module. Clears any saved / loaded key.
cmkey --zpsk
.........................Zeroize the crypto unit PSK.
8.1.4
Key Commands
cmkey --save
.........................Save key to non-volatile memory location (0-31).
cmkey -e
..................................Encrypted DEK (data encryption key) 40 byte value represented
by 80 hex characters.
cmkey -m
..................................MAC (message authentication code) 32 byte value represented
by 64 hex characters.
cmkey -p
..................................Plain Text PSK (pre-shared key) 32 byte value represented by 64
hex characters.
cmkey -d
..................................Plain Text DEK (data encryption key) 32 byte value represented
by 64 hex characters.
cmkey -k
..................................Generates KEK (key encryption key.
cmkey -u
..................................User defined plain text PSK (pre-shared key) 32 byte value
represented by 64 hex characters.
8.2
DTS1
CAUTION
CONFIGURATION ACCESS. Before attempting to setup or configure the DTS1, the Write-Enable
switch
MUST
be in the
READ-WRITE
position.
Before attempting to configure the DTS1, set the write-enable switch to the
READ-WRITE
position. Refer to paragraph 3.2.2
for detailed location information. After
configuring the unit, set the write-enable switch to the
READ
position.
Refer to paragraph 12.3.11
for detailed information about
configuring the DTS1.