A key that is protected under the master key is in operational form, which means ICSF can use it in cryptographic functions on the system.
When you store a key with a file or send it to another system, the key is enciphered under a transport key rather than the master key because, for security reasons, the key should no longer be active on the system. When ICSF enciphers a key under a transport key, the key is not in operational form and cannot be used to perform cryptographic functions.
When a key is enciphered under a transport key, the sending system considers the key in exportable form. The receiving system considers the key in importable form. When a key is reenciphered from under a transport key to under a system's master key, it is in operational form again.
The Key Token Build, Key Token Build2, Key Generate, Key Generate2, Key Import, Data Key Import, Clear Key Import, Multiple Clear Key Import, Secure Key Import, Secure Key Import2, Multiple Secure Key Import, Symmetric Key Import, Symmetric Key Import2, and TR-31 Import callable services can create an operational key form.
For more information about the key types, see either Functions of symmetric cryptographic keys or the z/OS Cryptographic Services ICSF Administrator's Guide. See Key Forms and Types Used in the Key Generate Callable Service for more information about key form.