Expected values
  • 23 Jan 2025
  • 2 Minutes à lire
  • Sombre
    Lumière
  • PDF

Expected values

  • Sombre
    Lumière
  • PDF

The content is currently unavailable in French. You are viewing the default English version.
Résumé de l’article

  Table: Attribute values expected for the customer keys
Key roleHSM storage keyHSM transport keyKEK
Key typeCKK_DES2 or
CKK_DES3 or
CKK_AES(5)
CKK_DES2 or
CKK_DES3 or
CKK_AES(5)
CKK_DES2 or
CKK_DES3 or
CKK_AES(5)
Key size128(DES2) or
192(DES3) or
128(AES128) or
256(AES256)
128(DES2) or
192(DES3) or
128(AES128) or
256(AES256)
128(DES2) or
192(DES3) or
128(AES128) or
256(AES256)
PersistentTRUETRUETRUE
Private (P)FALSE (3)FALSE (3)FALSE
Sensitive (T)TRUETRUETRUE
Modifiable (M)FALSEFALSEFALSE
Wrap (W)TRUEFALSEFALSE
Unwrap (U)TRUETRUEFALSE (4)
Extractable (X)FALSEFALSEFALSE
Export (w)FALSEFALSETRUE
Exportable (x)FALSE (1)TRUEFALSE (1)
Import (I)FALSEFALSEFALSE
Derive (R)FALSEFALSEFALSE
Encrypt (E)TRUE (2)TRUE (2)FALSE
Decrypt (D)FALSEFALSEFALSE
Sign (S)FALSEFALSEFALSE
Verify (V)FALSEFALSEFALSE

(1): Can be TRUE if key backup should be possible.

(2): Can be FALSE for VACMAN Controller 3.7 and later (Encrypt is no longer mandatory).

(3): Can be TRUE for VACMAN Controller 3.6.11 and later. See Private keys for information about private keys.

(4): Can be TRUE if the KEK must be able to import wrapped keys.

(5): 3DES triple-length or AES highly recommended (3DES double-length is not supported in case of ProtectServer2 HSM, if the HSM has been configured with the FIPS Algorithm Only flag enabled).

  Table: Meaning of key attributes
AttributeMeaning
PersistentIndicates whether a key object has been created for all the sessions. If FALSE, the key is only visible for the current session and will be destroyed when the session ends.
PrivateIndicates whether users need to authenticate to the key’s HSM token before they can access the key object.
SensitiveIndicates whether the key object can be extracted from the hardware security module (HSM) in clear. The key object includes the values of all key attributes.
ModifiableIndicates whether a key object can be changed after creation. Changing the key object involves changing the object’s attributes.
WrapIndicates whether the key can encrypt other keys that are in the HSM.
UnwrapIndicates whether the key can decrypt encrypted key material that is in the HSM.
ExtractableIndicates whether the key can be extracted from the HSM in encrypted form. The key encrypting key can be controlled by any user of the HSM. It is recommended that you use the Exportable rather than the Extractable property.
ExportThis attribute is similar to the Wrap attribute in that it specifies that the key may be used to encrypt a second key so that it may be extracted from the HSM in an encrypted form. Unlike the Wrap attribute, however, only the security officer may specify this attribute.
ExportableIndicates whether the key can be exported from the HSM in encrypted form. However, the key encrypting key needs to be controlled by a security officer, not by a standard user.
ImportThis attribute is similar to the Unwrap attribute. It is used to determine if a given key can be used to unwrap encrypted key material. The important difference is that if Import is set to TRUE and Unwrap is set to FALSE, then the only unwrap mechanism that can be used will be 3DES in CBC-mode.
DeriveIndicates whether other keys can be derived from the key.
EncryptIndicates whether the key can be used to encrypt data.
DecryptIndicates whether the key can be used to decrypt data.
SignIndicates whether the key can be used to generate digital signatures or message authentication codes (MACs).
VerifyIndicates whether the key can be used to verify digital signatures or message authentication codes (MACs).

Cet article vous a-t-il été utile ?

What's Next
Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Ozzy, facilitant la découverte de connaissances grâce à l’intelligence conversationnelle