Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Rotate encryption keys

Prev Next

Introduction

If your company requires rotation of encryption keys, then use the Admin Console or nnl-mgmt.sh to manage your tenants’ encryption keys. If your company doesn’t have such a policy, there is no need for you to use this feature.

The Digipass S3 Server uses symmetric encryption, based on the encryption key, to encode temporary state information needed for protocol operations. This information is exchanged with the client.

There can be only one active encryption key per tenant. When a new key is created, it is automatically activated and the previous active key is made obsolete.

Using the Admin Console

  1. Login and, if needed, switch to the desired tenant. Navigate to Configuration > Encryption Keys.

  2. Click Add Key/Alias to add an encryption key. The Add Key dialog opens.

    • If you are not using the Crypto plugin, click Add Encryption Key.

      1. To auto-generate an encryption key, select the Autogenerate checkbox and click Save.

      2. To create your own key

        1. Clear the Autogenerate checkbox.

        2. Enter the required key in the Key text box and click Save.

    • If you are using the Crypto plugin, click Add Key Alias, enter the alias for your key and click Save.

Using nnl-mgmt.sh

Use nnl-mgmt.sh's key add command to create and activate a new credential encryption key. The example below creates and activates a new encryption key for the marketing tenant.

./nnl-mgmt.sh key add -tenantid marketing

There are additional commands to list keys, delete a key, and activate a key. See details at nnl-mgmt.sh's key add command.