Working with Key Stores
You can use the following procedures to view and manage Key Stores:
To translate a Key Store
- Prompt (F4) the command of CRYPTO/TRNKEYSTR. The Translate Key Store (TRNKEYSTR) panel appears.
- Press F1 on any parameter for complete online help text.
- Press Enter after the parameter values are entered.
To display Key Store attributes
The DSPKEYSTR command allows authorized users to display the attributes for a Key Store. This is primarily useful for viewing the Master Encryption Key (MEK) id number and version in which the Key Store entries are encrypted with.
Do the following steps to view a Key Store’s attributes:
- Prompt (F4) the command of CRYPTO/DSPKEYSTR. The Display Key Store Attributes (DSPKEYSTR) panel appears.
- Enter the Key Store name to display, and then press Enter.
- The Key Store’s attributes will be displayed.
- Press F1 on any parameter for complete online help text.
To delete a Key Store
Since a Key Store is created as a validation list (*VLDL) object on the IBM i, you can delete a Key Store by using IBM’s DLTVLDL (Delete Validation List) command.
To delete the Key Store, the user must have authority to the DLTVLDL command and must have *OBJEXIST rights to the Validation List object.
Do the following steps to delete a Key Store:
- Backup the Validation List (*VLDL) object to backup media or to a Save File object.
- Prompt (F4) the command of DLTVLDL.
- Specify the Key Store name and library, and then press Enter.