Entrust nShield: Creating and managing cryptographic keys

Prev Next

There are three utilities available to create and manage HSM keys for Entrust nShield:

  • KeySafe. To create sensitive data keys.

  • generatekey. To create sensitive data keys and secure auditing keys.

  • OneSpan Key Management Tool for Entrust nShield. To create storage data keys, key encryption keys, and transport keys. It is installed with OneSpan Authentication Server and can only be run after the OneSpan Authentication Server setup, but should run before finishing the OneSpan Authentication Server Configuration Wizard.

    It is available in two versions:

    • manager-5. This is the most recent version 5. It is mandatory if you are using nShield 5, but is also compatible with nShield XC models if they are using a recent firmware version.

    • manager-xc. This is the previous version 4. It only supports nShield XC and should be used if you are using models with older firmware and Security World versions.

    For a detailed comparison of the different Key Management Tool versions, see Key Management Tool versions.

If you are using Entrust nShield HSM devices with OneSpan Authentication Server, the protection type for all sensitive data keys, storage data keys, and audit data keys must be set to module (as opposed to softcard or token). When you use the generatekey command, you can accomplish this by using the protect=module parameter.