Configuring The Tks To Associate The Master Key With Its Version - Red Hat CERTIFICATE SYSTEM 7.2 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.2 - ADMINISTRATION:
Table of Contents

Advertisement

Chapter 8. Token Key Service
tksTool -W -d . -n new_master -t transport -o file
Enter Password or Pin for "NSS Certificate DB":
Retrieving the transport key (for wrapping) from the specified token . . .
Generating and storing the master key on the specified token . . .
Naming the master key "wrapped_master" . . .
Successfully generated, stored, and named the master key!
Using the transport key to wrap and store the master key . . .
Writing the wrapped data (and resident master key KCV) into the
file called "file" . . .
wrapped data:
master key KCV: CED9 4A7B
(computed KCV of the master key residing inside the wrapped data)
5. Use the transport key to unwrap a master key called new_master stored in a file called file.
tksTool -U -d . -n new_master -t transport -i file
Enter Password or Pin for "NSS Certificate DB":
Retrieving the transport key from the specified token (for
unwrapping) . . .
Reading in the wrapped data (and resident master key KCV) from
the file called "file" . . .
wrapped data:
master key KCV: CED9 4A7B
(pre-computed KCV of the master key residing inside the wrapped data)
Using the transport key to temporarily unwrap the master key to
recompute its KCV value to check against its pre-computed KCV value . . .
master key KCV: CED9 4A7B
(computed KCV of the master key residing inside the wrapped data)
master key KCV: CED9 4A7B
(pre-computed KCV of the master key residing inside the wrapped data)
Using the transport key to unwrap and store the master key on the
specified token . . .
Naming the master key "new_master" . . .
Successfully unwrapped, stored, and named the master key!
Using the tksTool is explained in more detail in the Certificate System Command-Line Tools Guide.
8.3. Configuring the TKS to Associate the Master Key with
Its Version
Master keys have a numeric identifier such as 01. The TKS maps these IDs to PKCS #11 object
nicknames specified in masterKeyId. To map the keys, add a mapping parameter like the following
to the CS.cfg file:
tks.mk_mappings.#02#01=tokenname:masterKeyId
184
47C0 06DB 7D3F D9ED
FE91 7E6F A7E5 91B9
47C0 06DB 7D3F D9ED
FE91 7E6F A7E5 91B9

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Table of Contents