IBM WebSphere XS40 Command Reference Manual page 254

Datapower xml security gateway
Table of Contents

Advertisement

gen-object
object-name name
gen-sscert
days number-days
file-name name
export-key
export-sscert
password plaintext
password-alias alias
using-key name
The following parameters are available on HSM-equipped appliances:
hsm
hsm-name name
exportable mechanism
Guidelines
CA policies can vary with regard to the amount of information that is required in
the CSR. Check with the CA before generating the CSR to ensure that you provide
sufficient information.
228
Command Reference
Creates a crypto key management object. To create a crypto certificate
management object use the gen-sscert property.
Optionally specifies the names for the objects that are created by the
gen-object property. If not specified, the value for the commonName
property is used.
Optionally creates a self-signed certificate in addition to the private key
and CSR.
Optionally specifies the validity period in days for the self-signed
certificate. The default is 365 days.
Optionally specifies a common prefix for the generated private key, CSR,
and self-signed certificate. If not specified, the value for the object-name
property is used.
Optionally creates a copy of the private key in the temporary: directory in
addition to the one in the cert: directory.
Optionally creates a copy of the self-signed certificate in the temporary:
directory in addition to the one in the cert: directory.
Optionally specifies the password to 3DES-encrypt the private key when it
is saved to a file.
Optionally specifies a password alias in an existing password map file.
This alias is used to 3DES-decrypt the password.
Optionally specifies an existing key object to sign the CSR and any
self-signed certificate that is generated. The point of this parameter is to
reissue a new CSR or self-signed certificate with the existing key material
to do the signature.
Optionally creates the private key on the HSM instead of in memory.
Optionally specifies a label for the key created on the HSM. If not
specified, the value of the object-name parameter is used.
Optionally indicates the mechanism that can be used to export the
imported object at a later time. Only keys will be exportable with the
defined mechanism. The only supported mechanism is hsmkwk.

Advertisement

Table of Contents
loading

Table of Contents