Ê SHA384-RSA-PKCS, keySize={1024,2048}, sign, verify
Ê SHA512-RSA-PKCS, keySize={1024,2048}, sign, verify
Ê DES2-KEY-GEN, keySize={128,128}, generate
Ê DES3-KEY-GEN, keySize={192,192}, generate
Ê DES3-ECB, keySize={24,24}, encrypt, decrypt
Ê DES3-CBC, keySize={24,24}, encrypt, decrypt
Ê DES3-MAC, keySize={24,24}, sign, verify
Ê DES3-MAC-GENERAL, keySize={24,24}, sign, verify
Ê MD5, digest
Ê MD5-HMAC, sign, verify
Ê SHA-1, digest
Ê SHA-1-HMAC, sign, verify
Ê SHA256, digest
Ê SHA256-HMAC, sign, verify
Ê SHA224, digest
Ê SHA384, digest
Ê SHA384-HMAC, sign, verify
Ê SHA512, digest
Ê SHA512-HMAC, sign, verify
Ê TLS-PRE-MASTER-KEY-GEN, hw, generate
Ê TLS-MASTER-KEY-DERIVE, hw, derive
Ê TLS-KEY-AND-MAC-DERIVE, hw, derive
Ê TLS-MASTER-KEY-DERIVE-DH, hw, derive
Ê mechtype-0x378, hw, derive
Ê mechtype-0x500, hw, sign
Ê AES-KEY-GEN, keySize={16,32}, generate
Ê AES-ECB, keySize={16,32}, encrypt, decrypt
Ê AES-CBC, keySize={16,32}, encrypt, decrypt
Ê AES-MAC, keySize={16,32}, sign, verify
Ê AES-MAC-GENERAL, keySize={16,32}, sign, verify
Слот JC2SE-Laser на JaCarta-2 SE поддерживает генерацию ключевой пары длиной 1024 и
2048 бит (RSA-PKCS-KEY-PAIR-GEN).
3.2.1. Генерируем ключевую пару на токенах
Подключаем токен по одному и генерируем ключевую пару.
для Rutoken ECP
user@ipa ~ $ pkcs11-tool --module /usr/lib64/p11-kit-proxy.so \
Ê --pin 12345678 --login --keypairgen --key-type rsa:2048 --id 7001 \
Ê --label rt_2fa_ipa
Using slot 32 with a present token (0x30)
Key pair generated:
Private Key Object; RSA
Ê label: rt_2fa_ipa
Ê ID: 7001
Ê Usage: decrypt, sign, unwrap
Ê Access: sensitive, always sensitive, never extractable, local
16