Key Labels for APPC Encryption
The following key labels are used for the key-encrypting keys:
CM@LU@IM.netid1.cpname1.netid.luname
CM@LU@EX.netid1.cpname1.netid.luname
- CM is a constant prefix
- @ is a constant delimiter
- LU identifies an LU key-encrypting key
- IM identifies an importer key-encrypting key
- EX identifies an exporter key-encrypting key
- netid1.cpname1 is the fully qualified name of the local node where the key-encrypting key will be used
- netid.luname is the fully qualified name of the partner LU
Note: In APPC, an independent LU can initiate a session
(primary LU) or it can be secondary when the partner LU initiates
the LU 6.2 session. If the LU initiates a session, an exporter KEK
is required in key storage. Otherwise, an importer KEK will be used.