Administration Security Officer (ASO)

This user knows and can present the Admin Token SO PIN. The ASO’s main role is to introduce the Administrator to the module. The following services are available to the ASO:

>Set the initial Administrator PIN value (ASO cannot change it later)

>Set the CKA_TRUSTED attribute on a Public object

>Set the CKA_EXPORT attribute on a Public object

>Exercise cryptographic services with Public objects

>Create, destroy, import, export, generate and derive Public objects

>Can change his/her own PIN