CKM_DES3_CBC
Firmware 7.8.4 and Newer Summary
| FIPS approved? | Yes |
| Supported functions | Encrypt | Decrypt | Wrap | Unwrap |
| Functions restricted from FIPS use | Cannot wrap | Cannot encrypt |
| Minimum key length (bits) | 128 |
| Minimum key length for FIPS use (bits) | 192 |
| Minimum legacy key length for FIPS use (bits) | 128 |
| Maximum key length (bits) | 192 |
| Block size | 8 |
| Digest size | 0 |
| Key types | DES3 |
| Algorithms | DES3 |
| Modes | CBC |
| Flags | Extractable |
NOTE
>The 3DES usage counter attribute (CKA_BYTES_REMAINING) has been removed in Luna HSM Firmware 7.8.4 and newer, to comply with FIPS 140-3 requirements. This attribute is now ignored on any keys where it is already set.
>In this firmware version, "Functions restricted from FIPS use" has changed for this mechanism, to comply with FIPS 140-3 requirements.
Firmware 7.7.0-7.8.1 Summary
| FIPS approved? | Yes |
| Supported functions | Encrypt | Decrypt | Wrap | Unwrap |
| Functions restricted from FIPS use | Cannot wrap |
| Minimum key length (bits) | 128 |
| Minimum key length for FIPS use (bits) | 192 |
| Minimum legacy key length for FIPS use (bits) | 128 |
| Maximum key length (bits) | 192 |
| Block size | 8 |
| Digest size | 0 |
| Key types | DES3 |
| Algorithms | DES3 |
| Modes | CBC |
| Flags | Extractable |
NOTE
The attribute is preserved through backup/restore using a Luna Backup HSM 7; restoring the key restores the counter's setting at the time of backup.
The attribute is not preserved through backup/restore using a Luna Backup HSM G5; restoring the key resets the counter to the maximum.
NOTE To comply with FIPS SP800-131a Rev2 published in March 2019, when the HSM is in FIPS mode, this mechanism is not allowed to wrap objects.
Firmware 7.4.2 and Older Summary
| FIPS approved? | Yes |
| Supported functions | Encrypt | Decrypt | Wrap | Unwrap |
| Functions restricted from FIPS use | None |
| Minimum key length (bits) | 128 |
| Minimum key length for FIPS use (bits) | 192 |
| Minimum legacy key length for FIPS use (bits) | 128 |
| Maximum key length (bits) | 192 |
| Block size | 8 |
| Digest size | 0 |
| Key types | DES3 |
| Algorithms | DES3 |
| Modes | CBC |
| Flags | Extractable |