2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
36
SV3800, SV3800B, and SV3800B-20 Security Policy
Key
Key Type
Generation/
Input
Output
Storage
Use
Master key
AES CBC 256
bit key
Internally
generated using
DRBG
Never exits the
module
Encrypted using
KEK1 and stored
on main disk
Used to encrypt
KEK2s
Key-encrypting
key 2 (KEK2)
AES CBC 256
bit key
Internally
generated using
DRBG
Never exits the
module
Encrypted using
associated
master key and
stored on main
disk
Used to encrypt
object encryption
keys
Object
Encryption key
AES CBC 256
bit key
Internally
generated using
DRBG
Never exits the
module
Encrypted
using
associated
KEK2 and
stored on main
disk
Encrypt data and
other CSPs for
storage
RSA public
key
3
RSA 2048 and
3072 bits
Internally
generated using
DRBG or can be
imported in
plaintext
During TLS or
SSH negotiation
in plaintext
Stored in
plaintext on
internal disk
Negotiating TLS
or SSH
management
sessions
RSA
private key
RSA 2048 and
3072 bits
Internally
generated using
DRBG or can be
imported in
plaintext
Never exits the
module
Stored in
plaintext on
internal disk
Negotiating TLS or
SSH management
sessions
HSM public key RSA 2048 and
3072 bits
imported
Imported over
TLS
Exported in
encrypted
backup
Encrypted with
associated
object
encryption key
and stored on
internal disk
HSM resigning
during SSL/TLS
inspection
3
The Crypto Officer shall only import RSA 2048 bit or larger keys.