Restrictions

The restrictions for CSNBT31X.

  • The only proprietary values for the TR-31 header fields supported by this verb are those values defined and used by IBM® CCA when carrying a control vector in an optional block in the header.
  • AES is not currently supported for TR-31 key blocks.
  • The export is prohibited if the CCA key does not have attributes XPORT-OK (CV bit 17 = B'1') and T31XPTOK (CV bit 57 = B'1').
  • As of CCA 5.4 and CCA 6.2, this verb supports three-key TDES keys. As a key management service this includes triple-length TDES key encrypting keys (KEKs). For a list of supported triple-length TDES key types beginning with Release 5.4 and Release 6.2, see Table 1.
  • TR-31 tokens can only be used in the source_key_identifier, unwrap_kek_identifier, and wrap_kek_identifier starting in CCA 8.1 and newer releases. In addition, starting with CCA 8.1, this service can output an internal TR-31 key block (parameter tr31_key_block).
Note: The only partial key tokens that may be exported are CCA DES key tokens when using either the ATTRCV or INCL-CV rules. This behavior may be prohibited by enabling the access control point X’006E’ (T31X - Disallow Partial DES Key Export with CV in IBMC01 OB).