Restrictions

The restrictions for CSNDSYG.

As of CCA 5.4 and CCA 6.2, this verb supports three-key TDES keys. As a key management service this includes triple-length TDES key encrypting keys (KEKs). For a list of supported triple-length TDES key types, see Table 1.

The hardware configuration sets the limit on the modulus size of keys for key management. Thus, this verb will fail if the RSA key modulus bit length exceeds this limit.

Specification of keyword PKA92 with an input NOCV key-encrypting key token is not supported. There is also no support for TR-31 tokens when using the PKA92 keyword.

TR-31 tokens can only be used with this verb starting with CCA 8.1. Furthermore, they may only be used in parameter key_encrypting_key_identifier to wrap a generated locally enciphered key, and in parameter local_enciphered_key_identifier as a skeleton token in order to generate a locally enciphered TR-31 key. The output RSA-enciphered blob in parameter RSA_enciphered_key must still contain a control vector.