Manage the Cryptography Keys

This section explains how to manage the cryptography keys used to protect sensitive information and assure integrity of data in the ActivID Appliance database.

The keys are managed in consistent key set of five keys for the following roles:

  • AUDIT – Audit signature

  • CREDS – User credentials are encrypted with the key role (replaces the des and DeviceSecretsKey keys of previous versions of the ActivID Appliance)

  • DSIGN – Database row integrity signature (DataSignature)

  • SESSION – sessions (ALSI)

  • SYS – System credentials (adapter parameters) (replaces the ParameterValueKey key of previous versions of the ActivID Appliance)

Note:  
  • The renewal process might take several minutes during which the audit data will be archived and deleted, the database re-encrypted and the applications restarted.
  • It is recommended that you back up the appliance and archive the audit data before renewing the keys.

Renew the Software Keys

  1. Log on to the ActivID Console and, under System in the left menu, select Cryptography.

  1. Click Renew Keys.

  1. Click Yes, proceed.

  1. Wait for the renewal process to complete.

  1. Click Done.

Renew the External HSM Keys

  1. Log on to the ActivID Console and, under System in the left menu, select Cryptography.

  1. Click Renew Keys.

  1. Click Yes, proceed.

  2. Wait for the renewal process to complete.

  1. Click Done.

Note: For further information about configuring and managing an external HSM, see Managing External HSMs.