The procedures presented in this chapter involving the RSA master
key will depend on whether your system has any coprocessors with the
Sep. 2011 or later LIC installed (CEX3C and later) and online. If
your system has any coprocessors with the Sep. 2011 or later LIC online,
the RSA-MK will be processed in the same manner as the DES, AES, and
ECC master keys.
If your system has any CEX3C coprocessors with the Sep. 2011 or
later LIC online:
- The PKA callable services control will not be used on your system.
It will not appear on the Administrative Control Functions panel.
- The RSA-MK will not be set when the final key part is loaded on
the Master Key Entry panel. The master key will be in the new master
key register.
- The TKE Workstation cannot be used to set the RSA-MK.
- PKDS initialization will use the new master key register to get
the verification pattern of the RSA-MK to be stored in the PKDS header
record. The RSA-MK will be activated as part of PKDS initialization.
- The RSA-MK can be loaded on a coprocessor (new or after the master
keys are cleared) and set by using the Set MK utility on the Master
Key Management panel.
If your system doesn’t have any CEX3C coprocessors with the Sep.
2011 or later LIC: