11KVL4000–ConvertingEncryption
Keys
ThischapterisapplicableonlyifyourKVLisconguredtoworkinbothASNandASTRO
®
25modesof
operation.
IfyourKVLisconguredtoworkinbothASNandASTRO
®
25modesofoperation,youcanconvertencryption
keysbetweenthesetwomodes.ConvertingkeysallowsyoutocopyanASNTrafcorShadowkeyfromitsASN
memorylocation(storedtoaPIDandcontainingaLID)andloaditintoanemptyASTRO
®
25TEKorKEK
memorylocation(storedtoaCKRandcontainingaKID),andtheotherwayaround.
11.1WhentoConvertKeys
ConvertingkeysisusedmostcommonlyforcopyingkeysbetweenASNandASTRO
®
25intheKVLmemory.
TheremaybeoccasionswhenyouhaveanexistingkeyinanASNmemorylocationandwishtoduplicateitforuse
onanASTRO
®
25target.ByconvertingthekeyfromtheASNmemorytoASTRO
®
25memorywithintheKVL,
yousavetheeffortofrecreatingthekeyintheASTRO
®
25memoryandreenteringtheencryptionkeydata.You
mayalsoconvertkeysfromtheASTRO
®
25memoryandloadthemintotheASNmemory.
11.2KeyConvertingRestrictionsandGuidelines
Observethefollowingrestrictionsandguidelineswhenconvertingkeys:
•OnlykeyswithAES-256,DES-OFB,DES-XL,DVP-XL,andDVI-XLalgorithmscanbeconverted.
•TEKsofthesamealgorithmtypestoredinASTRO
®
25memorycannothaveduplicateKIDs(including
0000).
•TrafcKeys(ASN)canbeconvertedonlytoTrafcEncryptionKeys(TEK)locationsinASTRO
®
25
memory(andtheotherwayaround);ShadowKeys(ASN)canbeconvertedonlytoKeyEncryptionKeys
(KEK)locationsinASTRO
®
25memory(andtheotherwayaround).
•Keyscanbeconvertedonlytoanemptymemorylocation;overwritingisnotallowed.
•Keysmustbeconvertedoneatatime.
11.3ConvertingaKeyfromASNtoASTRO25
Prerequisites:
OnlyanAdministratorcanconvertkeys.
ProcedureSteps
6871018P37-F-January2013
11-1