-
Create a new directory
ECC_keyfiles/for keeping ECC reference key files. -
Make sure
exampleecc.netexists. If not, create similarly toexample.net. -
Generate the key file for KSK.
|
›_ Console |
|---|
|
Where the parameter:
-
-l specifies the key label in pkcs11 URI format.
-
-f specifies the key flag.
-
-a is the algorithm.
-
exampleecc.netis the name of zone file.
Key file generation for the KSK key
-
Generate the key file for ZSK.
|
›_ Console |
|---|
|
Key file generation for the ZSK key
Where the parameter:
-
-l specifies the key label in pkcs11 URI format.
-
-f specifies the key flag.
-
-a is the algorithm.
-
exampleecc.netis the name of zone file.
-
Verify that you have two KSK and two ZSK key files available.
|
›_ Console |
|---|
|
List files
The .private file contains a reference to the HSM object, not the private key itself.