Key encryption keys are used to encrypt and protect other cryptographic keys and can be generated with the OneSpan Key Management Tool for Entrust nShield.
To create a key encryption key for Entrust nShield 5
Open a terminal window.
Start the OneSpan Key Management Tool for Entrust nShield, by default:
/opt/vasco/ias/bin/hsm-ncipher/manager/n5/manager-5
Select an HSM ID to use for the key creation process.
Insert the administrator or operator card into a card slot.
Enter the ID of the slot in which the administrator/operator card is inserted.
Select option 14, i.e., (14) Generate a Key Encryption Key.
Follow the on-screen instructions provided by the Key Management Tool to complete the storage data key configuration.
To create a key encryption key for Entrust nShield XC
Open a terminal window.
Start the OneSpan Key Management Tool for Entrust nShield, by default:
/opt/vasco/ias/bin/hsm-ncipher/manager/xc/manager-xc
Select an HSM ID to use for the key creation process.
Insert the administrator or operator card into a card slot.
Enter the ID of the slot in which the administrator/operator card is inserted.
Select option 3, i.e., (3) Generate a Key Encryption Key.
Follow the on-screen instructions provided by the Key Management Tool to complete the storage data key configuration.