IdExchange 1.9.1

Generating the IDMS secret key with the Thales/nCipher HSM

The IDMS uses an AES key stored within the HSM to perform cryptographic operations. The instructions below describe the process to the the Thales generateKey utility.

Requirement: The IDMS requires a 256 AES key with the label of PIVIDMSAES be available. 

*Note: The instructions below provide guidance for generating the key. The key specifications may be different for each environment depending on the organizations security policy.

Steps

  1. generatekey --generate --batch PKCS11 type=AES size=256 plainname=PIVIDMSAES ident=PIVIDMSAES

    image-20240824-133004.png


  2. Restart the NFAST Server

  3. Restart the IDMS