Key Labels for APPC Encryption

The following key labels are used for the key-encrypting keys:
CM@LU@IM.netid1.cpname1.netid.luname

CM@LU@EX.netid1.cpname1.netid.luname
  • CM is a constant prefix
  • @ is a constant delimiter
  • LU identifies an LU key-encrypting key
  • IM identifies an importer key-encrypting key
  • EX identifies an exporter key-encrypting key
  • netid1.cpname1 is the fully qualified name of the local node where the key-encrypting key will be used
  • netid.luname is the fully qualified name of the partner LU
Note: In APPC, an independent LU can initiate a session (primary LU) or it can be secondary when the partner LU initiates the LU 6.2 session. If the LU initiates a session, an exporter KEK is required in key storage. Otherwise, an importer KEK will be used.