Generate Digital Signatory Keys on an HSM

When activating a PIV, PIV-I or CIV card, ActivID CMS uses digital signatory parameters to sign PIV objects (user-related data required by PIV such as CHUID Card Holder Unique Identifier or fingerprints that are securely stored on the card). Cryptographic keys used in the digital signature of PIV objects can be generated and stored on an HSM. To generate the signatory keys on an HSM, a utility is available in the ActivID CMS distribution, in the Tools\PIV\DigitalSignatoryKeyOnHSM directory.