On systems that support the ECC master key, you can add the ECC
master key to any existing PKDS. It is also possible to add the RSA
master key to a PKDS that was initialized with only the ECC master
key.
There are two options for updating the PKDS on the PKDS Operations
panel.
- Option 3 will add the missing master key verification pattern
to the PKDS header record. The PKDS will not become the active PKDS
and the master key will not be set. Use this option if you have more
than one PKDS to update as a PKDS cannot be updated if the new master
key register is empty. The last PKDS should be processed using option
4.
- Option 4 will add the missing master key verification pattern,
make the specified PKDS the active PKDS and set the master keys. This
option should be used if you have only one PKDS to update or to update
the last of your PKDSs after all other PKDSs have been updated using
option 3.
These are the steps to update the PKDS:
- Load the new ECC master key by using the master key entry panels
or by using TKE. The ECC master key must be loaded on all active coprocessors.
- From the ICSF Primary Menu panel, select
option 2, MASTER KEY MGMT.
- From the CSFMKM10 — Key Data Set Management panel, select option
2 for PKDS MK MANAGEMENT.
- The CSFMKM30 — PKDS Management panel appears, select option
1, PKDS OPERATIONS.
- The CSFCKD30 — PKDS Operations panel appears. In the PKDS
field, enter the name of an existing, initialized PKDS.
- If updating multiple PKDS, for all but the last PKDS, choose option
3, Update an existing PKDS, and press ENTER. ICSF will check the status
of the new master key registers and the master key verification pattern
of the master key is written to the PKDS header record.
Note: All
the PKDSs that you wish to update should be processed prior to going
to step 6.
- If updating the last or only PKDS, choose option 4, Update an
existing PKDS and activate master keys, and press ENTER. ICSF will
check the status of the new master key registers and that the master
key verification pattern of the master key is written to the PKDS
header record. The PKDS will become the active PKDS and set the master
key.