IBM Support

IBM i External Key Management: Getting Started with IBM Key Protect and Master Key Parts

How To


Summary

IBM i Cryptographic Services integrates with IBM Key Protect for IBM Cloud to support external key management and secure storage of cryptographic key material. This guide walks through configuring an External Key Manager Description (EKMD), generating 256-bit AES keys in IBM Key Protect, and loading those keys as IBM i master key parts. By completing these steps, you will learn how to use IBM Key Protect as a secure repository for cryptographic keys and master key material.

Objective

This guide provides a step-by-step walkthrough for configuring external key management between IBM i Cryptographic Services and IBM Key Protect for IBM Cloud. After completing the guide, you will be able to:

  • Configure an External Key Manager Description (EKMD)

  • Generate 256-bit AES keys in IBM Key Protect

  • Load Key Protect keys as IBM i master key parts

  • Set an IBM i master key using externally managed key parts

Environment

System requirements:

  • IBM i Version 7.6

  • An instance of the IBM Key Protect for IBM Cloud service. For more information on using IBM Key Protect for IBM Cloud, see the Key Protect documentation.
  • The Cryptographic Services Key Management interfaces in IBM Navigator for i require a TLS-secured session. For more information on setting up TLS, see Enabling TLS for IBM Navigator for i.
  • Required PTFs for External Key Management

PTF

Product

Notes

MJ09820

5770999

Delayed Apply

MJ09843

5770999

 

MJ09828

5770999

Delayed Apply

MJ09827

5770999

Delayed Apply

MJ09825

5770999

Delayed Apply

MJ09823

5770999

Delayed Apply

MJ09745

5770999

 

MJ09824

5770999

 

MJ10009

5770999

Delayed Apply

SJ09822

5770SS1

 

SJ09900

5770SS1

 

SJ09821

5770SS1

 

SJ09830

5770SS1

Should pull in the rest due to requisites

SJ09836

5770SS1

 

SJ09911

5770SS1

 

SJ10116

5770SS1

 

SJ10591

5770SS1

 

SJ10004

5770SS1

 

Steps

Step 1: Create an external key manager description file

An external key manager description (EKMD) file is a password-protected stream file that stores the connection information IBM i needs to communicate with the Key Protect service. Before creating an EKMD, gather the following information:

  • Key Protect instance ID - the UUID that identifies the Key Protect instance
    • Can be found on the overview page of the Key Protect service

      Finding the instance ID on the Key Protect overview page

  • Authentication endpoint - The Identity and Access Management (IAM) endpoint used to authenticate with IBM Cloud
    • Unless you use private endpoints, use iam.cloud.ibm.com for the authentication endpoint
  • Service endpoint - The Key Protect regional endpoint
    • Both the private and public endpoints can be found on the overview page of the Key Protect service

      Finding the service endpoints on the Key Protect overview page

  • API Key - Your IBM Cloud API key
    • Use the following procedure to create a new API key:
      1. Log in to your IBM Cloud account.
      2. In the Manage menu, select Access (IAM).
      3. In the API keys menu, click Create button.
      4. In the Create IBM Cloud API key page, enter a name and description for your API Key.
      5. Copy the API key to a secure storage location, such as a password manager.

Once you have gathered the required information, you can create the EKMD file using the Manage External Key Manager Description Files interface in Navigator for i or with the Create EKM Description (CRTEKMD) command. 

Creating a new EKMD file in Navigator for i

 

Step 2: Generate a 256-bit AES key in IBM Key Protect

The next step is to create a standard encryption key in IBM Key Protect. Generate a new 256-bit AES key, which will later be used as a master key part on IBM i.

  1. Log in to your IBM Cloud account.
  2. From the navigation menu, go to Resource List to view a list of your resources.
  3. From your IBM Cloud resource list, select your provisioned instance of Key Protect.
  4. To create a new key, click Add and select the Create a key option.
  5. Specify the key name and, optionally, an alias. An alias provides a more meaningful identifier for the key and can make it easier to locate and manage later. Without an alias, the key is typically identified by its 36-character UUID.

  6. When you are finished filling out the key's details, click Add key to confirm.
Adding a new key in Key Protect

 

Step 3: Load the Key Protect key as a system master key part

Once the key has been exported to IBM Key Protect, it can be loaded as a system master key part. This capability enables secure backup and recovery of master key parts and simplifies distribution of master key material across multiple systems. To load a Key Protect key as a master key part, use the Load EKM Key action in the Manage Master Keys panel of Navigator for i or use the Add Master Key Part (ADDMSTPART) command.

It is recommended to use multiple master key parts instead of relying on a single part. Using multiple parts can help strengthen operational controls by distributing responsibility for master key material and reducing dependence on a single source for key recovery. 

Important: Always use 256-bit (32-byte) AES keys as master key parts. Although IBM Key Protect generates AES-256 keys by default, imported AES-128 and AES-192 keys can also be stored in Key Protect. Using an imported AES-128 or AES-192 key as a master key part reduces the effective strength of the resulting master key and is not recommended.

Loading an EKM key part

 

Step 4: Set the system master key

After the desired master key parts have been loaded, use the Set Master Key (SETMSTKEY) command or the Manage Master Keys panel in IBM Navigator for i to set the master key. The set operation activates the key material that was loaded into the new version of the master key. After the operation completes, the new version becomes the current version and is used for cryptographic operations that require the master key.

Each master key version has an associated Key Verification Value (KVV). The KVV is a 24-byte hash of the master key value that can be used to identify a specific master key version without revealing the key itself. KVVs are commonly used to determine whether a master key has changed and to identify which master key version was used during an encryption operation. To view the KVV for a master key, use the Check Master Key Verification Value (CHKMSTKVV) command or the Properties window in the Manage Master Keys panel in IBM Navigator for i.

Setting a master key for the first time
When a master key is being set for the first time, the current version is empty and the new version contains the loaded master key parts. During the set operation, the new version becomes the current version.

Before setting:

New version of master key 5

After setting:

current version of master key 5

In this example, the key material in the new version of master key 5 becomes the current version of master key 5.

Replacing an existing master key

If a current master key already exists, the set operation preserves the previous value by moving it to the old version. The new version then becomes the current version.

Before setting:

New and current version of master key 5

After setting:

current and old version of master key 5

In this example, the existing current version of master key 5 is moved to the old version, and the new version becomes the current version. The old version serves as a record of the previously active master key value. To restore that value as the current master key, the master key parts must be loaded again and the master key reset.

Additional Information

As an alternative to generating master key parts in IBM Key Protect, you can use IBM i to generate and securely back up master key parts. First, create a root key in IBM Key Protect. Next, use the Generate EKM Key (GENEKMKEY) command to generate a random 256-bit AES key and wrap it with the root key. The wrapped key ciphertext is stored in an IFS stream file, allowing the master key part to be securely backed up and later restored. The stream file can be specified when loading a master key part by using the Add Master Key Part (ADDMSTPART) command or the Manage Master Keys interface in IBM Navigator for i.

Example of GENEKMKEY command:

GENEKMKEY EKMD('/home/user/ekmd') EKMPWD() ROOT('My-AES-Root-Key') STMF('/home/user/wrapped-part-for-MK5')

Loading a wrapped key part in Navigator for i:

Loading a wrapped key part

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB68","label":"Power HW"},"Business Unit":{"code":"BU070","label":"IBM Infrastructure"},"Product":{"code":"SWG60","label":"IBM i"},"ARM Category":[{"code":"a8m0z0000000CIrAAM","label":"Cryptography-\u003ECryptographic Services"},{"code":"a8m0z0000000CH1AAM","label":"IBM Navigator for i"}],"ARM Case Number":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"and future releases;7.6.0"}]

Document Information

Modified date:
09 September 2026

UID

ibm17282538