Required commands

The required commands for CSNDPKD.

This verb requires the PKA Decrypt command (offset X'011F') to be enabled in the active role.

The use of a CRYSTALS-Kyber or ML-KEM private key in the PKA_key_identifier parameter requires the PKA Decrypt - Allow ML-KEM, CRYSTALS-Kyber keys command (offset X'0084') to be enabled in the active role.

The PKA Decrypt verb also requires the following commands to be enabled in the active role to disallow the unwrapping of an encrypted key that has been formatted:

Required commands for the PKA Decrypt verb

Rule-array keyword Offset Command
PKCS-1.2 X'020A' PKA Decrypt - Disallow PKCS-1.2
ZERO-PAD X'020B' PKA Decrypt - Disallow ZEROPAD
PKCSOAEP X'020C' PKA Decrypt - Disallow PKCSOAEP