If it is already external (wrapped by a KEK), it can be translated to another 
KEK with CSNDPKT. Also, it can be created in external form via CSNDPKG and then 
imported into multiple systems but, unfortunately, there is no method to export 
an RSA private key once it is already MK-encrypted.

ECC and QSA private keys can be exported with CSNDPKT.

Eric Rossman
---------------------------------
ICSF Security Architect
z/OS Security
---------------------------------

-----Original Message-----
From: IBM Mainframe Discussion List <[email protected]> On Behalf Of 
Lennie Bradshaw
Sent: Saturday, January 31, 2026 7:13 PM
To: [email protected]
Subject: [EXTERNAL] Re: Moving a PKDS Key

Eric,
Is there no way that the private key can be transferred by using a common 
transport key. I have this for a DES encryption key some years ago.
Lennie

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to