-
Generate the RSA key using p11tool2.
|
›_ Console |
|---|
|
Key generation output
-
Verify that the keys are generated onto the HSM using following command.
|
›_ Console |
|---|
|
Example
Key list using p11tool2
-
Generate a self-signed certificate.
|
›_ Console |
|---|
|
Here LUKS is the token label and LUKSPrivateKey is the key on the HSM. Provide Cryptouser PIN when prompted.
Self sign certificate generation
It is recommended to use CA signed certificate for production environment.
-
Convert
lukscert.pemtolukscert.derformat.
|
›_ Console |
|---|
|
Certificate type change output
-
Import the certificate.
|
›_ Console |
|---|
|
Certificate import using p11tool2
-
Check the certificate on HSM.
|
›_ Console |
|---|
|
Certificate list output