The IDMS uses an AES key stored within the HSM to perform cryptographic operations. The instructions below describe the process to the the Thales generateKey utility.
Requirement: The IDMS requires a 256 AES key with the label of PIVIDMSAES be available.
*Note: The instructions below provide guidance for generating the key. The key specifications may be different for each environment depending on the organizations security policy.
Steps
-
generatekey --generate --batch PKCS11 type=AES size=256 plainname=PIVIDMSAES ident=PIVIDMSAES
-
Restart the NFAST Server
-
Restart the IDMS