payShield 10K Installation and User Guide
©Thales Group
Page 375
All Rights Reserved
•
Exportability: See the Exportability
Table in the
Host Programmer's
Manual
.
•
Optional Block data.
•
Exportability of exported key (if
exporting).
Outputs:
•
Key encrypted under an
appropriate variant of the selected
LMK.
•
Key/Key Block encrypted under
the ZMK (if exporting).
•
Key Check Value.
•
Key Block containing the key encrypted
under the selected LMK.
•
Key/Key Block encrypted under the
ZMK (if exporting).
•
Key Check Value.
Notes:
For legacy reasons, the export of a ZMK, ZEK or DEK from encryption under
a key block LMK to encryption under a ZMK (in variant/X9.17 format) will not
be permitted. Specifically, such export of keys with key usage = "K0", "52",
"D0", "21" or "22" will be prohibited.
Errors:
•
Invalid LMK identifier - no LMK loaded or entered identifier out of range.
•
Must be in Authorized State or Activity not authorized - the key type
provided requires the
HSM to be in Authorized State.
•
Data invalid; please re-enter - the encrypted ZMK does not contain the
correct characters, or the key check value does not contain 6 hexadecimal
characters. Re-enter the correct number of hexadecimal characters.
•
Key parity error; please re-enter - the ZMK does not have odd parity on
each byte. Re-enter the encrypted ZMK and check for typographic errors.
•
Invalid key scheme for key length - the Key scheme is inappropriate for Key
length.
•
Invalid key scheme - the key scheme is invalid.
•
Invalid key type; re-enter - the key type is invalid. See the Key Type Table
the
Host Programmer's Manual
.
•
Internal failure 12: function aborted - the contents of LMK storage have
been corrupted or erased. Do not continue. Inform the Security Department.
•
Various key block field errors – the value entered is invalid, or incompatible
with previously entered values.
Example 1:
(Variant LMK)
This example generates a new double length DES key.
Online>
KG
<Return>
Enter LMK id:
00
<Return>
Enter key length [1,2,3]:
2
<Return>
Enter key type:
002
<Return>
Enter key scheme (LMK):
U
<Return>
Enter key scheme (ZMK):
<Return>
Enter ZMK:
<Return>
Key under LMK: U YYYY YYYY YYYY YYYY YYYY YYYY YYYY YYYY
Key Check value: ZZZZZZ
Online>