SSM Option 5 - Encryption Key Maintenance
This option allows you to create, update and delete the keys used to encrypt files on the database.
When you select Option 5 on the SSM screen, the following screen is displayed.
Encryption Key Maintenance -------------------------------------------------------------------------------- Reality Encryption Key ID > 1. Encryption Type 2. Encryption Key Enter Encryption ID. (or 'CR' to exit or '?' for list.
At the prompt, do one of the following:
-
Enter the ID of a key to create, update or delete. Encryption key IDs can consist of alphanumeric upper and lower case characters only (they are case sensitive) - no other characters are permitted.
Caution
If you change or delete an existing encryption key, the files that use it will no longer be accessible.
-
Type
?
to list the defined keys. -
Press RETURN to return to the SSM screen.
The cursor waits at the prompt until you do this. On entering the ID, the screen displays the selected key if this already exists.
The following is an example of the screen displayed for the new encryption key CUSTOMERS:
Encryption Key Maintenance -------------------------------------------------------------------------------- Reality Encryption Key ID >CUSTOMERS *NEW ITEM* 1. Encryption Type DES 2. Encryption Key Enter option# (1-2) to change; EX to exit; FI to file; FD to delete :
Do one of the following:
-
Enter the number of an attribute in the key.
-
Type
EX
to return to TCL without creating or modifying the key. -
Type
FI
to save the displayed key item. A message is displayed to remind you to backup your REK file and store it in a secure off-site location - press return to continue. -
Type
FD
to delete the displayed key item from the file.
All other responses result in an error message. For each option selected, an information prompt is displayed in the middle of the screen along with a help message at the bottom of the screen. Input is entered at the information prompt and depends on the field you have selected. If you enter a question mark (?
), a help message is displayed and you are re-prompted for input.
Encryption key maintenance options
The type of encryption key.
Prompt:
Select encryption type (1=DES, 2=DES3) :
Enter 1
for DES:CBC or 2
for Triple DES.
The encryption key that will protect your data.
Prompt:
Enter n character encryption key :
Enter an 8-character encryption key for DES:CBC, or a 16-character key for Triple DES.