Skip to main content
Skip table of contents

Generating the IDMS secret key

The IDMS uses an AES key stored within the HSM to perform cryptographic operations. The instructions below describe the process to the the SafeNet CKDemo Utility to generate the key.

Requirement: The IDMS requires a 256 AES key with the label of PIVIDMSAES be available. 

*Note: The instructions below provide guidance for generating the key. The key specifications may be different for each environment depending on the organizations security policy.

Step NumberProcedureExample
1Using a command prompt, browse to the LunaClient directory and run the CKDEMO application.

2Select the appropriate slot.

3Specify the user.

4Perform the login and provide the password to the partition.
5Select 45 to generate the key.

6Select 16 for AES.

7Set the length of the key to 32.

8List the keys. Change the key label to "PIVIDMSAES".
9Once complete the AES key should be listed at PIVIDMSAES.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.