---
title: "Entrust nShield: Creating a Key Encryption Key"
slug: "oas-iglnx-entrust-nshield-creating-a-key-encryption-key-3-28"
updated: 2025-07-04T10:04:24Z
published: 2025-07-07T13:49:52Z
canonical: "docs.onespan.com/oas-iglnx-entrust-nshield-creating-a-key-encryption-key-3-28"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onespan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Entrust nShield: Creating a Key Encryption Key

Key encryption keys are used to encrypt and protect other cryptographic keys.

To create a key encryption key (Entrust nShield)

1. Open a terminal window.
2. Start the OneSpan Key Management Tool for Entrust nShield, by default /opt/vasco/ias/bin/manager-xc.
3. Select an HSM ID to use for the key creation process.
4. Insert the administrator or operator card into a card slot.
5. Enter the ID of the slot in which the administrator/operator card is inserted.
6. Select option 3, i.e. (3) Generate a Key Encryption Key.

The OneSpan Key Management Tool for Entrust nShield will walk you through the configurations of the key encryption key.
