Chapter 4 Administering the Sun Crypto Accelerator 4000 Board With the vcaadm andvcadiag Utilities 79
Rekeying a Sun Crypto Accelerator 4000 Board
Over time, it may be necessary because of your security policy to use new keys as
the master key or remote access key.The rekey command allows you to regenerate
either of these keys, or both.
Rekeying the master key also causes the keystore to be reencrypted under the new
key,and invalidates older backed up master key files with the new keystore file. It is
advisable to make a backup of the master key whenever it is rekeyed. If you have
multiple Sun Crypto Accelerator 4000 boardsusing the same keystore, you will need
to backup this new master key and restore it to the other boards.
Rekeying the remote access key logs the security officer out, forcinga new
connection that uses the new remote access key.
Youmay specify one of three key types when issuing the rekey command:
The following is an example of entering a key type of all with the rekey
command:
TABLE4-6 KeyTypes
KeyType Action
master Rekey the master key.
remote Rekey the remoteaccess key. Logs the security officer out.
all Rekeys both master and remoteaccess keys.
vcaadm{vcaN@hostname,sec_officer}> rekey
Key type (master/remote/all): all
WARNING: Rekeying the master key will render all old board backups
useless with the new keystore file. If other boards use this
keystore, they will need to have this new key backed up and
restored to those boards. Rekeying the remote access key will
terminate this session and force you to log in again.
Rekey board? (Y/Yes/N/No) [No]: y
Rekey of master key successful.
Rekey of remote access key successful. Logging out.