Generates the key pair and the certificate signing request (CSR) of the certificate for signing OCSP responses.
evactl create-key -k <key_type> [-s <subject>] [-o <csr>] [-p <pin>] [-t <token>] [-v <vendor>] [-y]For example:
$ sudo evactl create-key -k RSA2048 -s "CN=97357462, O=Entrust, C=ES"Starting PKCS #11 pod... DoneUsing token with label mytokenCreated key with id 4a00a4617d1afd5ad626955132dd0d396a69ed24CSR:-----BEGIN CERTIFICATE REQUEST-----MIICqDCCAZACAQAwMzExMC8GA1UEAxMoNGEwMGE0NjE3ZDFhZmQ1YWQ2MjY5NTUx…etTv+pac+nJKW8fw-----END CERTIFICATE REQUEST-----See below for a description of each option.
-k <key_type>
Create a key of the <key_type> type, where <key_type> is the key identifier.
See the table below for the supported RSA key types.
Key type identifier | Key algorithm | Modulus size |
|---|---|---|
RSA2048 | RSA | 2048 bits |
RSA3072 | RSA | 3072 bits |
RSA4096 | RSA | 4096 bits |
See the table below for the supported ECDSA key types.
Key type identifier | Key algorithm | Curve |
|---|---|---|
ECDSAP256 | ECDSA | NIST P-256 |
ECDSAP384 | ECDSA | NIST P-384 |
ECDSAP521 | ECDSA | NIST P-521 |
See table below for the supported ML-DSA key types.
Key type identifier | ML-DSA key |
|---|---|
ML-DSA-44 | ML-DSA-44 key pair |
ML-DSA-65 | ML-DSA-65 key pair |
ML-DSA-87 | ML-DSA-87 key pair |
See table below for the supported composite key types.
Key type identifier | ML-DSA key | Classical algorithm | Classical parameter | Signature scheme | Hash |
|---|---|---|---|---|---|
MLDSA44-RSA2048-PSS-SHA256 | ML-DSA-44 key pair | RSA | 2048 bits | RSA-PSS | SHA-256 |
MLDSA44-RSA2048-PKCS15-SHA256 | ML-DSA-44 key pair | RSA | 2048 bits | RSA PKCS#1 v1.5 | SHA-256 |
MLDSA44-ECDSA-P256-SHA256 | ML-DSA-44 key pair | ECDSA | NIST P-256 | ECDSA | SHA-256 |
MLDSA65-RSA3072-PSS-SHA512 | ML-DSA-65 key pair | RSA | 3072 bits | RSA-PSS | SHA-512 |
MLDSA65-RSA3072-PKCS15-SHA512 | ML-DSA-65 key pair | RSA | 3072 bits | RSA PKCS#1 v1.5 | SHA-512 |
MLDSA65-RSA4096-PSS-SHA512 | ML-DSA-65 key pair | RSA | 4096 bits | RSA-PSS | SHA-512 |
MLDSA65-RSA4096-PKCS15-SHA512 | ML-DSA-65 key pair | RSA | 4096 bits | RSA PKCS#1 v1.5 | SHA-512 |
MLDSA65-ECDSA-P256-SHA512 | ML-DSA-65 key pair | ECDSA | NIST P-256 | ECDSA | SHA-512 |
MLDSA65-ECDSA-P384-SHA512 | ML-DSA-65 key pair | ECDSA | NIST P-384 | ECDSA | SHA-512 |
MLDSA87-RSA3072-PSS-SHA512 | ML-DSA-87 key pair | RSA | 3072 bits | RSA-PSS | SHA-512 |
MLDSA87-RSA4096-PSS-SHA512 | ML-DSA-87 key pair | RSA | 4096 bits | RSA-PSS | SHA-512 |
MLDSA87-ECDSA-P384-SHA512 | ML-DSA-87 key pair | ECDSA | NIST P-384 | ECDSA | SHA-512 |
MLDSA87-ECDSA-P521-SHA512 | ML-DSA-87 key pair | ECDSA | NIST P-521 | ECDSA | SHA-512 |
Mandatory: Yes.
-s <subject>
Use <subject> as the Subject of the certificate request. Where <subject> is either:
- A full Distinguished Name (DN)
- A Relative Distinguished Name (RDN).
The DN attributes must be in capital letters for the Subject to be recognized.
For example:
CN=Example User,O=Example,C=USCN=Example UserMandatory: No. When omitting this option, the Subject in the generated certificate request defaults to the following:
CN=<key_id>Where <key_id> is the key identifier.
-o <csr>
Save the certificate signing request (CSR) in a file with the <csr> path.
The root user owns generated files, so you must change their permissions to download them using SFTP – for example, sudo chmod 644 config.tar.gz
Mandatory: No. When omitting this option, the command prints the CSR to the standard output.
-p <pin>
Authenticate in the HSM with the <pin> PIN.
Mandatory: No. When omitting this option, the command looks for the PIN in the application secrets. If not found, prompts the user for the PIN.
-t <token>
Select the HSM token with the <token> label.
Mandatory: No. When omitting this option, the command uses the value of the Token label configuration parameter.
The command will raise an error if you omit this option and the configuration is not loaded.
-v <vendor>
Use the <vendor> security module. See the following table for the supported values.
Vendor | Security module |
|---|---|
none | Built-in software PKCS #11 module. |
nshield | nShield HSM. See HSM requirements for the supported models. |
thales | Thales HSM. See HSM requirements for the supported models. |
epicom | Epicom HSM. See HSM requirements for the supported models. |
It is recommended to select a Hardware Security Module (HSM).
Mandatory: No. When omitting this option, the command assumes the value of the Vendor configuration parameter.
The command will raise an error if you omit this option and the configuration is not loaded.
-y, --yes
Skip the confirmation prompt.