Phase 3 for cloning a master key: Establishing the target node and cloning a master key
Using the designated nodes, establish the target node and clone the master key following the steps for cloning the master key mentioned in Table 1. This coprocessor can also serve as the SA node.
Phase | Node | Task | ✓ |
---|---|---|---|
At the target node | |||
3a.1 | Target | Audit the appropriateness of the access controls. | |
3a.2 | Target | Perform time synchronization and ensure that the fcv_td2k.crt authorization is installed. | |
3a.3 | Target | Confirm the coprocessor serial number:
|
|
3a.4 | Target | Ensure the existence of a (temporary) master key. | |
3a.5 | Target | If not already established, enter the environment
ID (EID):
|
|
3a.6 | Target | If not already established, set the number m and n shares
values:
|
|
3a.7 | Target | Using the facilities of your operating system, erase the csr.db data file. | |
3a.8 | Target | Generate the CSR key:
|
|
3a.9 | Target | Register the SA public-key hash:
|
|
3a.10 | Target | Register the SA public-key:
|
|
At the SA node | |||
3b.1 | SA | Certify the CSS key (as required):
|
|
3b.2 | SA | Certify the CSR key:
|
|
At the source node | |||
3c.1 | Source | Obtain at least the number of m and n shares.
Perform the following substep for each share. Note that logon and
logoff might be required to obtain each share.
Repeat as required. |
|
At the target node | |||
3d.1 | Target | Install the number of m and n shares. Perform
the following for each share and observe the response. The response
indicates when enough shares have been installed to form the new master
key. Note that logon and logoff might be required to install each
share.
Observe the response. Loading sufficient shares completes the new master-key. Repeat as required. |
|
3d.2 | Target | Confirm the new master key:
|
|
3d.3 | Target | Erase the csr.db data file. This is not a security problem but rather to avoid complications while doing master key cloning operation. | |
3d.4 | Target | As appropriate, set the master key:
|