payShield 10K Installation and User Guide
©Thales Group
Page 422
All Rights Reserved
Transfer existing LMK to RLMK (XT)
Variant
Key Block
Online
Offline
Secure
Authorization:
Not required
Command:
XT
Function:
To transfer an existing HSM LMK stored on legacy smartcards to payShield
Manager RLMK cards for use through the payShield Manager.
In order to transfer a Variant LMK you will be required to fully reassemble the
LMK (bring all the components together). Then, the fully formed Variant LMK
is split among shares onto the pre-commissioned payShield Manager RLMK
cards.
For Key Block LMKs, they are not stored as components on non-payShield
Manager smart cards, but as shares. However, you must bring a quorum of
share holders together, reconstitute the LMK, and then split it among shares
onto the pre-commissioned payShield Manager RLMK cards.
Authorization:
The HSM must be in Secure state to run this command.
Inputs:
•
Number of shares to split LMK into
•
Number of Components required to reconstitute LMK
Outputs:
•
None
Example 1
:
Secure>
XT
<Return>
Please have all the local LMK components and enough
commissioned RACCs to receive the LMK ready.
Insert card and press ENTER:
<Return>
Enter PIN:
*****
<Return>
Check: 268604
Load more components? [Y/N]:
N
<Return>
LMK Check: 268604
LMK key scheme: Variant
LMK algorithm: 3DES(2key)
LMK status: Test
Is this the LMK you wish to transfer? [Y/N]:
Y
<Return>
Enter the number of shares to split the LMK into: [2-9]:
2
<Return>
The number of shares required to reconstitute the LMK:
[2-2]: 2 <Return>
Insert a commissioned card 1 of 2 and press ENTER:
<Return>
Enter PIN:
******
<Return>
Card Check: E0CBF4
LMK share written to smartcard.
Insert a commissioned card 2 of 2 and press ENTER:
<Return>
Enter PIN:
******
<Return>