To generate a storage data key, use the OneSpan Key Management Tool for Entrust nShield. This is a console utility installed with OneSpan Authentication Server, and can be used to generate (and manage) the following:
Storage data keys
Transport keys (to decrypt DPX files)
To create a storage data key for Entrust nShield 5
Open a terminal window.
Start the OneSpan Key Management Tool for Entrust nShield, by default:
/opt/vasco/ias/bin/hsm-ncipher/manager/n5/manager-5
Select an HSM ID to use for the key creation process.
Insert the administrator or operator card into a card slot.
Enter the ID of the slot in which the administrator/operator card is inserted.
Select option 12, i.e., (12) Generate a Storage Key.
Follow the on-screen instructions provided by the Key Management Tool to complete the storage data key configuration.
To create a storage data key for Entrust nShield XC
Open a terminal window.
Start the OneSpan Key Management Tool for Entrust nShield, by default:
/opt/vasco/ias/bin/hsm-ncipher/manager/xc/manager-xc
Select an HSM ID to use for the key creation process.
Insert the administrator or operator card into a card slot.
Enter the ID of the slot in which the administrator/operator card is inserted.
Select option 2, i.e., (2) Generate a Storage Key.
Follow the on-screen instructions provided by the Key Management Tool to complete the storage data key configuration.
For more information, refer to the HSM Key Management Guide for Entrust nShield (included with the Authentication Suite Server SDK).