- 24 Jan 2025
- 1 Minute à lire
- Impression
- SombreLumière
- PDF
Customer key attributes
- Mis à jour le 24 Jan 2025
- 1 Minute à lire
- Impression
- SombreLumière
- PDF
This chapter provides information about the attributes for the customer keys for usage with Authentication Suite Server SDK for Entrust nShield HSM, and as configured when using Key Management Tool.
It is recommended to create FIPS 140-2 Level 3 Security World for higher level of security.
In FIPS 140-2 Level 3 security world, it is required either the ACS or an OCS to authorize most operations, including the creation of keys.
In case of using FIPS 140-2 Level 3 Security World (strict FIPS 140-2 Level 3 mode), the new Entrust nShield HSMs based on PowerPCELF architecture (Entrust nShield XC) does not permit to generate keys being double-length 3DES keys (DES2).
In case of FIPS 140-2 Level 3 Security World, the Entrust nShield XC SMs can use existing DES2 keys already generated previously, but cannot generate new DES2 keys.