Loading the LMKs

Command: LK (Load Keys). The HSM must be in the Secure state.

Function:     To load an LMK component set from Smartcards.

Inputs:        Smartcards with LMK components.
PINs or passwords for the Smartcards.

Outputs:     Master key check value.

Errors:        Load failed check comparison – card is blank

Not a LMK card – card formatted for HSM settings or is a licence card

Card not formatted – card is not formatted

Smartcard error; command/return: 0003 – invalid PIN is entered

Invalid PIN; re-enter: - a PIN of less than 4 or greater than 8 is entered.

Example:

It is assumed that the HSM is set for Smartcard mode and Echo On (CS command).

Secure> LK  <Return>

LMKs must be erased before proceeding.

Erase LMKs? Y <Return>

Load LMK from components.
Insert card and enter PIN: *****  <Return>

CHECK: XXXX XXXX XXXX XXXX
Load more components? [Y/N]: Y <Return>

 

Remove the Smartcard. Insert the second and subsequent Smartcards and repeat the loading procedure. When all have been loaded and the HSM displays the check value, record the check value.

CHECK: XXXX XXXX XXXX XXXX
Load more components? [Y/N]: N <Return>

Use the LO command to load LMKs into key change storage;

Use the A command to put the HSM into the Authorised state in order to check the LMK components and passwords or PINs.