diff --git a/src/libmsc/a_iface.c b/src/libmsc/a_iface.c
index 69b4c09..cdd8d89 100644
--- a/src/libmsc/a_iface.c
+++ b/src/libmsc/a_iface.c
@@ -170,38 +170,18 @@
 
 /* Send Cipher mode command via A-interface */
 int a_iface_tx_cipher_mode(const struct gsm_subscriber_connection *conn,
-			   int cipher, const uint8_t *key, int len, int include_imeisv)
+			   struct gsm0808_encrypt_info *ei, int include_imeisv)
 {
 	/* TODO generalize for A- and Iu interfaces, don't name after 08.08 */
 	struct msgb *msg_resp;
-	struct gsm0808_encrypt_info ei;
+	uint8_t crm = 0x01;
 
 	OSMO_ASSERT(conn);
+	LOGPCONN(conn, LOGL_DEBUG, "Cipher Mode Command to BSC, %u ciphers (%s)",
+		 ei->perm_algo_len, osmo_hexdump_nospc(ei->perm_algo, ei->perm_algo_len));
+	LOGPC(DMSC, LOGL_DEBUG, " key %s\n", osmo_hexdump_nospc(ei->key, ei->key_len));
 
-	uint8_t crm = 0x01;
-	uint8_t *crm_ptr = NULL;
-
-	LOGPCONN(conn, LOGL_DEBUG, "Cipher Mode Command to BSC, cipher=%d key=%s\n",
-		 cipher, osmo_hexdump_nospc(key, len));
-
-	/* Setup encryption information */
-	if (len > ENCRY_INFO_KEY_MAXLEN || !key) {
-		LOGP(DMSC, LOGL_ERROR,
-		     "Cipher mode command message could not be generated due to invalid key! (conn_id=%i)\n",
-		     conn->a.conn_id);
-		return -EINVAL;
-	} else {
-		memcpy(&ei.key, key, len);
-		ei.key_len = len;
-	}
-
-	if (include_imeisv)
-		crm_ptr = &crm;
-
-	ei.perm_algo[0] = vlr_ciph_to_gsm0808_alg_id(cipher);
-	ei.perm_algo_len = 1;
-
-	msg_resp = gsm0808_create_cipher(&ei, crm_ptr);
+	msg_resp = gsm0808_create_cipher(ei, include_imeisv ? &crm : NULL);
 	LOGP(DMSC, LOGL_DEBUG, "N-DATA.req(%u, %s)\n", conn->a.conn_id, osmo_hexdump(msg_resp->data, msg_resp->len));
 
 	return osmo_sccp_tx_data_msg(conn->a.scu, conn->a.conn_id, msg_resp);
diff --git a/src/libmsc/gsm_04_08.c b/src/libmsc/gsm_04_08.c
index d71b48b..d2c56c5 100644
--- a/src/libmsc/gsm_04_08.c
+++ b/src/libmsc/gsm_04_08.c
@@ -3381,6 +3381,10 @@
 	return msc_gsm48_tx_mm_serv_rej(conn, cause);
 }
 
+/* For msc_vlr_set_ciph_mode() */
+osmo_static_assert(sizeof(((struct gsm0808_encrypt_info*)0)->key) >= sizeof(((struct osmo_auth_vector*)0)->kc),
+		   gsm0808_encrypt_info_key_fits_osmo_auth_vec_kc);
+
 /* VLR asks us to start using ciphering */
 static int msc_vlr_set_ciph_mode(void *msc_conn_ref,
 				 enum vlr_ciph ciph,
@@ -3410,8 +3414,18 @@
 	case RAN_GERAN_A:
 		DEBUGP(DMM, "-> CIPHER MODE COMMAND %s\n",
 		       vlr_subscr_name(conn->vsub));
-		return a_iface_tx_cipher_mode(conn, ciph, tuple->vec.kc, 8,
-					      retrieve_imeisv);
+		{
+			struct gsm0808_encrypt_info ei;
+
+			ei.perm_algo[0] = vlr_ciph_to_gsm0808_alg_id(ciph);
+			ei.perm_algo_len = 1;
+
+			memcpy(ei.key, tuple->vec.kc, sizeof(tuple->vec.kc));
+			ei.key_len = sizeof(tuple->vec.kc);
+
+			return a_iface_tx_cipher_mode(conn, &ei, retrieve_imeisv);
+		}
+
 	case RAN_UTRAN_IU:
 #ifdef BUILD_IU
 		DEBUGP(DMM, "-> SECURITY MODE CONTROL %s\n",
