When you import a key into the Cryptographic Security Platform Vault for Cryptographic APIs, the target key must be wrapped with RSA-AES.
To wrap a key for key import
Create an RSA-2048 key in the Cryptographic Security Platform Vault for Cryptographic APIs where you want to import the wrapped key. This will be the wrapping key.
Select the key that you created, and click Download Public Key to download the public part of the RSA-2048 key.
Generate the target AES-256 32-byte key using OpenSSL. For example:
$ openssl rand -out target_aes_key32Generate a temporary random AES-256 32-byte key using OpenSSL. For example:
$ openssl rand -out temp_aes_key32List the files that you've created or downloaded. For example:
root@machine-name-10-1-228-132import_key_sample2]# ls -lrttotal12-rw-r--r--.1root root451Aug511:15rsa_public.pem-rw-r--r--.1root root32Aug511:19temp_aes_key-rw-r--r--.1root root32Aug511:19target_aes_keyWrap the temporary AES key with the wrapping public key using the CKM_RSA_PKCS_OAEP algorithm. For example:
openssl pkeyutl -encrypt -pubin -inkey rsa_public.pem -in temp_aes_key -out wrapped_aes_key -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha1List the files again. For example:
[root@machine-name-10-1-228-132import_key_sample2]# ls -lrttotal12-rw-r--r--.1root root451Aug511:15rsa_public.pem-rw-r--r--.1root root32Aug511:19temp_aes_key-rw-r--r--.1root root32Aug511:19target_aes_key-rw-r--r--.1root root296Aug511:22wrapped_aes_keyWrap the target key with the temporary AES key using the CKM_AES_KEY_WRAP_PAD algorithm, and append it to the wrapped key. For example:
openssl enc -id-aes256-wrap-pad -iv A65959A6 -K $( hexdump -v -e'/1 "%02x"'< temp_aes_key ) -in target_aes_key >> wrapped_aes_keyList the files again. For example:
[root@machine-name-10-1-228-132import_key_sample2]# ls -lrttotal16-rw-r--r--.1root root451Aug511:15rsa_public.pem-rw-r--r--.1root root32Aug511:19temp_aes_key-rw-r--r--.1root root32Aug511:19target_aes_key-rw-r--r--.1root root296Aug511:22wrapped_aes_keyBase64-encode the wrapped AES key. For example:
[root@machine-name-10-1-228-132import_key_sample2]# openssl enc -base64 -A -in wrapped_aes_keyM65ZDVmHPMnT/bFE8idDaJnMeS+Pb/LB+vlJIsBCInnAI05UDtK0E7it6FoxAy0FdQsYmJYqJJuOVjkMGX/Uid8N6vDhpHaX2NAQcJsVZMas2sW03gUaeqXcrlOcDKzbCgAXbCovBMWEC46HZwqpiIZD8pqqRlxuMqb3m95/7TomPtZh7BYRbtWboJFtq1MAljzjwLTvUdcDZuMf03wHZhPZEaxrZKS68By2KLcHGS/oFvgSvAFH54doBJBRS2jPtir5hxo/lma4BQuKwCebRyf9ugOKlGjEJt2DEmTAPAWZ257TxXCinY9ooLTouGY4cdqBHimmTDVjgyg28u76poyqMZkUq9ZywVUf8onvEsaNSBERva3DbuoKEZSdbt/1MHg/L1031Rg=Copy the base64-encoded key into a file. This will be the key material used during the upload.
Remove any newline characters so the key is on a single line.