
Page 24 of 51
© Copyright 2017 Oracle Corporation
This document may be freely reproduced and distributed whole and intact including this Copyright notice.
Establish TLS Session
Establish connection with OKM
cluster
Permanent Encryption
Encryption Enabled
DRBG ‘Key’ Value – WRX
DRBG ‘V’ Value – WRX
DRBG Seed – WRX
TLS_PM – WRX
TLS_MS – WRX
TLS_EMK – W
TLS_DMK – W
TLS_ECK – W
TLS_DCK – W
CA_Cert – X
TDPubKey – X
TDPrivKey – X
Establish SSH session
Establish connection with
remote workstation
Permanent Encryption
Encryption Enabled
Encryption Disabled
Mixed Mode
SSH_HOST_PRIV – X
SSH_HOST_PUB - X
SSH_SK - WRX
SSH_SA - WRX
SSH_KEX_PRI - WRX
Export AES Key Wrap
Key (AKWK)
Export AKWK to the OKM
cluster
Permanent Encryption
Encryption Enabled
DRBG ‘Key’ Value – WRX
DRBG ‘V’ Value – WRX
DRBG Seed – WRX
AKWK – W
KWKPublicKey – X
TLS_EMK – X
TLS_ECK – X
Import
KWKPublicKey
Import the KWKPublicKey
from the OKM cluster onto the
module
Permanent Encryption
Encryption Enabled
KWKPublicKey – W
TLS_DMK – X
TLS_DCK – X
Import ME_Key
Import one or more ME_Keys
onto the module from the OKM
cluster
Permanent Encryption
Encryption Enabled
ME_Key – W
TLS_DMK – X
TLS_DCK – X
AKWK – X
2.4.4 Additional Operator Services
In addition to CO and User services, the module provides services to operators
that are not required to assume an authorized role. These services do not modify,
disclose, or substitute the keys and CSPs established in one of the Approved
modes. The overall security of the module is not affected by these services.
Table 5 lists the services available to operators not required to assume an
authorized role. These services are available in all Approved modes of operation.