Entrust nShield: Creating a transport key

Prev Next

Transport keys are used to protect DIGIPASS export file (DPX) data and can be generated with the OneSpan Key Management Tool for Entrust nShield. This is a console utility installed with OneSpan Authentication Server, and can be used to generate (and manage) the following:

  • Storage data keys

  • Transport keys (to decrypt DPX files)

To create a transport key for Entrust nShield 5

  1. Open a terminal window.

  2. Start the OneSpan Key Management Tool for Entrust nShield, by default:

    /opt/vasco/ias/bin/hsm-ncipher/manager/n5/manager-5

  3. Select an HSM ID to use for the key creation process.

  4. Insert the administrator or operator card into a card slot.

  5. Enter the ID of the slot in which the administrator/operator card is inserted.

  6. Select option 13, i.e., (13) Generate a Transport Key.

  7. Follow the on-screen instructions provided by the Key Management Tool to complete the transport key configuration.

To create a transport key for Entrust nShield XC

  1. Open a terminal window.

  2. Start the OneSpan Key Management Tool for Entrust nShield, by default:

    /opt/vasco/ias/bin/hsm-ncipher/manager/xc/manager-xc

  3. Select an HSM ID to use for the key creation process.

  4. Insert the administrator or operator card into a card slot.

  5. Enter the ID of the slot in which the administrator/operator card is inserted.

  6. Select option 4, i.e., (4) Generate a Transport Key.

  7. Follow the on-screen instructions provided by the Key Management Tool to complete the transport key configuration.

For more information, refer to the HSM Key Management Guide for Entrust nShield (included with the Authentication Suite Server SDK).