Entrust nShield: Creating a key encryption key

Prev Next

Key encryption keys are used to encrypt and protect other cryptographic keys and can be generated with the OneSpan Key Management Tool for Entrust nShield.

To create a key encryption key for Entrust nShield 5

  1. Open a terminal window.

  2. Start the OneSpan Key Management Tool for Entrust nShield, by default:

    /opt/vasco/ias/bin/hsm-ncipher/manager/n5/manager-5

  3. Select an HSM ID to use for the key creation process.

  4. Insert the administrator or operator card into a card slot.

  5. Enter the ID of the slot in which the administrator/operator card is inserted.

  6. Select option 14, i.e., (14) Generate a Key Encryption Key.

  7. Follow the on-screen instructions provided by the Key Management Tool to complete the storage data key configuration.

To create a key encryption key for Entrust nShield XC

  1. Open a terminal window.

  2. Start the OneSpan Key Management Tool for Entrust nShield, by default:

    /opt/vasco/ias/bin/hsm-ncipher/manager/xc/manager-xc

  3. Select an HSM ID to use for the key creation process.

  4. Insert the administrator or operator card into a card slot.

  5. Enter the ID of the slot in which the administrator/operator card is inserted.

  6. Select option 3, i.e., (3) Generate a Key Encryption Key.

  7. Follow the on-screen instructions provided by the Key Management Tool to complete the storage data key configuration.