PrivateKeyEntry with no CryptoHub UI step.
JSign consumes the CryptoHub token directly through the SunPKCS11 provider, so there is no separate Java KeyStore file to create or manage. The key and its certificate live on the appliance.
The JDK installation includes the
keytool application that enables you to run the keytool commands in this section with no additional configuration.Generate a key pair
Perform the following steps to generate a key pair on the CryptoHub:1
Export FXPKCS11_CFG so the Futurex PKCS #11 library can locate its configuration file (
fxpkcs11.cfg). Point it at the fxpkcs11.cfg you configured in Install and configure Futurex PKCS #11:Shell
On Windows, set
FXPKCS11_CFG as a machine-wide variable with setx instead (see Configure SunPKCS11 to use the Futurex PKCS11 module). If you set fxpkcs11.cfg in its default location, this step is not required.2
Execute the following command, passing the
pkcs11.cfg file you created in the previous section with -providerArg. Set -alias and -dname to a value that identifies this signing key:Text
On Windows, run the same command in a Command Prompt window and replace
/usr/local/etc/pkcs11.cfg with the path to your pkcs11.cfg file, such as C:\path\to\pkcs11.cfg.This command uses RSA 3072, which is the key size Futurex validated for this integration and the minimum that current code signing certificate requirements expect. RSA 2048 also works with this flow if your signing policy calls for it.
-sigalg SHA384withRSA sets the signature algorithm of the self-signed certificate that keytool creates alongside the key. It matches the SHA-384 digest the JSign examples use. It does not constrain the digest you pass to JSign later, so SHA256withRSA is also valid.The two -ext flags put the code signing extended key usage and the digitalSignature key usage on the generated certificate, which is what an Authenticode signing certificate requires.The keytool application generates the key pair on the CryptoHub and self-signs a certificate for it. With no
-storepass on the command line, keytool prompts for the KeyStore password.3
When prompted for the KeyStore password, enter the CryptoHub identity password (PKCS #11 PIN) configured inside the
<CRYPTO-OPR-PASS> tag in the fxpkcs11.cfg file.Let keytool prompt for the PIN rather than passing
-storepass on the command line. A PIN supplied as an argument is visible in your shell history and in the system process list.Verify the key pair
Run the following keytool command to confirm the key pair generated on the CryptoHub and lists aPrivateKeyEntry:
Shell
The response is similar to the following:
Shell
The subject distinguished name is unaffected by the alias form. It comes from
-dname, so CN=jsign-demo holds for any downstream check against the certificate subject.If
keytool -list reports 0 entries after a successful -genkeypair, the library is not pairing the certificate with the private key. Confirm you replaced the bundled FXPKCS11 4.59 library with 6.0 rev dc27 or later, and confirm both attributes(generate, ...) blocks are present in pkcs11.cfg.
