CKM_DES3_ECB_PAD

Supported Operations

Encrypt and Decrypt Yes
Sign and Verify No
SignRecover and VerifyRecover No
Digest No
Generate Key/Key-Pair No
Wrap and Unwrap Yes
Derive No
Available in FIPS Mode Yes
Restrictions in FIPS Mode

No Wrapping

Encrypt: A maximum limit of 228 64-bit packets can be processed by a single key. Once this limit is reached, an error (CKR_KEY_NOT_ACTIVE) occurs.

Key Size Range (bytes) and Parameters

Minimum 16
FIPS Minimum 16
Maximum 24
Parameter None

Description

This is a padding mechanism. Implemented padding mechanisms are:

>CKM_CAST128_ECB_PAD

>CKM_DES_ECB_PAD

>CKM_DES3_ECB_PAD

>CKM_IDEA_ECB_PAD

>CKM_RC2_ECB_PAD

These block cipher mechanisms are all based on the corresponding Electronic Code Book (ECB) algorithms, implied by their name, but with the addition of the block-cipher padding method detailed in PKCS#7.

These mechanisms are supplied for compatibility only and their use in new applications is not recommended.

PKCS#11 version 2.20 specifies mechanisms for Chain Block Cipher algorithms with and without padding and ECB algorithms without padding, but not ECB with padding.  These mechanisms fill this gap. The mechanisms may be used for general data encryption and decryption and also for key wrapping and unwrapping (provided all the access conditions of the relevant keys are satisfied).

Return to ProtectToolkit-C Mechanisms