
through the Derive Key service. PRNG3DES Key (PRNGKey)= This 3DES2Key is used for
seeding the X9.17 Pseudo-random Number Generator (PRNG). The PRNG 3DES Key is
generated randomly using the hardware random number generator (RNG) within the FastMap
processor. This key is generated every time a random number is needed for key generation
or as a direct request through the Generate Random Number service. The PRNG 3DES EDE
Key is destroyed after each PRNG is generated. RSA Public and Private Key Pair (SPK, VPK)=
This RSA key pair is generated by either the SO or User role for the purpose generating RSA
digital signatures through the RSA Sign service, or for verifying the same through the RSA
Verify service. A key pair which is designated by the user who created it cannot be used for
any other purpose such as key exchanges or encryption/decryption of data. The user may
specify through Boolean attributes whether the private key may be used for Signature
Generation and/or Data Decryption, and whether the public key may be used for Signature
Verification and/or Data Encryption. Hence, a given key pair may be used for both signatures/
verifications as well as data encryption/decryption. In FIPS 140-1 Mode, data encryption/
decryption is not available. RSA Encryption/Decryption Public and Private Key Pair (EPK,
DPK)= This key pair is generated by either the SO or User role for the purpose of encrypting
and decrypting data. When creating this key pair, the user may specify through Boolean
attributes whether the private key may be used for Signature Generation and/or Data
Decryption, and whether the public key may be used for Signature Verification and/or Data
Encryption. Hence, a given key pair may be used for both signatures/verifications as well as
data encryption/decryption. Note that in the FIPS 140-1 Mode, although Encryption/Decryption
key pairs may be generated, the RSA Encrypt and RSA Decrypt services are not available,
and therefore, such keys are not usable in this mode. Key-Wrapping-Key Share (KWKShare)
= Key share obtained by splitting the KWK into two shares with the Split Key service. Two
corresponding shares may be combined with the Combine Key service to enter the KWK into
the module.
9.0 Roles and Services
9.1 Roles
The HSM supports two roles. These are the User role and the Security Officer role. Each role
has a username and an iKey ID that are selectable by the security officer. The module must
be handled in a secure manner prior to initialization because authentication is not required to
initialize the module. Cryptographic keys and user-defined data which is created by a specific
authenticated user cannot be deleted or modified by another user, regardless of the role. For
example, a specific user of the User role may not delete or modify keys or data created by a
different user of either the User or SO roles. The SO and User roles cannot operate
simultaneously. Only one authenticated user is allowed at a time.
9.0 Roles and Services
User Guide
April 2013 227
Содержание 3050-VM
Страница 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Страница 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Страница 12: ...12 User Guide April 2013 ...
Страница 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Страница 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Страница 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Страница 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Страница 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Страница 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Страница 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Страница 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Страница 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Страница 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Страница 265: ...This will print current statistics every 3 seconds Monitoring the Port Forwarder User Guide April 2013 265 ...
Страница 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Страница 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...