- 06 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Creating and managing cryptographic keys
- Mis à jour le 06 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Cryptographic keys can be managed with the Administration Web Interface via SERVERS > Key Management.
If you have a large number of keys, you can use the FILTER button to filter the list by Key ID, Key Usage, or both. To return to the full list of keys, click CLEAR FILTER.
Click on any key to view its details.
To activate a key, click ACTIVATE. This initiates the Rotate Key wizard that allows you to run or schedule a key rotation.
Creating cryptographic keys
You can create a new cryptographic key with the Administration Web Interface.
To create a new cryptographic key
Log on to the Administration Web Interface.
- Select SERVERS > Add New Key.
- Type a key ID.
- Select a Usage purpose (Storage Data or Sensitive Data).
- Enter the Key Label or Key Value.
- If you have set up HSM, you will also need to enter the respective SlotID and KCV.
- For private keys, type the Token Label and PIN.
- Type a brief Description of the new key.
- Click CREATE.
Rotating cryptographic keys
You can rotate keys individually or as a bulk operation. Both procedures only differ in how they are initiated.
To configure key rotation
Log on to the Administration Web Interface.
To initiate key rotation for a single key:
- Select SERVERS > Key Management.
- Click on the key you want to rotate.
- Click ACTIVATE.
Alternatively, to initiate a bulk key rotation:
- Select SERVERS > Rotate Key.
- Select the Key Rotation Type (either Storage or Sensitive Data).
- Select the key to rotate and click NEXT.
On the Schedule Task page. select when and how you wish to run the key rotation:
- Run immediately. The key rotation is performed immediately in foreground. You will be unable to use the Administration Web Interface until the rotation is complete.
- Run in background. The key rotation is performed in background. Optionally, you can specify a time and date to schedule the operation. When selecting this option, you can also choose to be notified on completion.
Click NEXT to continue.
- Click Finish.