Run the generate-key.sh script after configuring an nShield HSM and before deploying a solution that uses this HSM, or before retrying a failed deployment. This script:

  1. Prompts you for the OCS (Operator Card Set) passphrase.
  2. Checks whether the kmdata.tar configuration file contains a wrapping key.
  3. Generates the key and updates the kmdata.tar configuration file if the key does not exist.

See Downloading the installation files for instructions on obtaining this script.