
Page 21 of 51
© Copyright 2017 Oracle Corporation
This document may be freely reproduced and distributed whole and intact including this Copyright notice.
Table 3 – Cryptographic Officer Services
Service
Description
Approved Mode
CSP and Type of
Access
Enable Permanent
Encryption Mode
Provide public and private keys in
order to connect to OKM; Enable
encryption
Encryption Enabled
Encryption Disabled
CA_Cert – WX
TDPrivKey – W
TDPubKey – W
Enable Encryption
Enabled Mode
Provide public and private keys in
order to connect to OKM; Enable
encryption
Encryption Disabled
CA_Cert – WX
TDPrivKey – W
TDPubKey – W
Enable Encryption
Disabled Mode
Turn encryption off; OKM
services are enabled
Encryption Enabled
Mixed Mode
CA_Cert – WX
TDPrivKey – W
TDPubKey – W
Enable Mixed Mode
Bring the module into a Mixed
mode of operation
Encryption Disabled None
Configure Module
Perform routine module
configuration
Permanent Encryption
Encryption Enabled
Encryption Disabled
Mixed Mode
None
Place drive
online/offline
Add or remove Fibre Channel and
iSER connectivity to the ETD
Permanent Encryption
Encryption Enabled
Encryption Disabled
Mixed Mode
None
Load Firmware
Update module firmware
Permanent Encryption
Encryption Enabled
Encryption Disabled
Mixed Mode
FSPubKey – RX
FSRootCert – X
Reset
Zeroization of all keys and CSPs
Permanent Encryption
Encryption Enabled
Encryption Disabled
Mixed Mode
All Keys and CSPs
25
–
W
Access Module via
Virtual Operator’s
Panel (VOP)
Log into VOP and manage the
module
Permanent Encryption
Encryption Enabled
Encryption Disabled
Mixed Mode
None
Create Dump
(Encrypted)
Create an encrypted dump file and
save to EEPROM
26
Permanent Encryption
Encryption Enabled
DRBG
27
‘Key’ Value –
WRX
DRBG ‘V’ Value –
WRX
DRBG Seed – WRX
DEKey – WX
DEPubKey – X
25
Dump excludes DEPubKey, FSPubKey, and FSRootCert
26
EEPROM – Electronically Erasable Programmable Read-Only Memory
27
DRBG – Deterministic Random Bit Generator