Skip to main content
This section uses Java keytool to generate a new code signing key pair on the CryptoHub, which JSign uses later to sign artifacts. On FXPKCS11 6.0 rev dc27 or later, this single command generates the key pair on the CryptoHub and produces a usable PrivateKeyEntry with no CryptoHub UI step. JSign consumes the CryptoHub token directly through the SunPKCS11 provider, so there is no separate Java KeyStore file to create or manage. The key and its certificate live on the appliance.
The JDK installation includes the keytool application that enables you to run the keytool commands in this section with no additional configuration.

Generate a key pair

Perform the following steps to generate a key pair on the CryptoHub:
1
Export FXPKCS11_CFG so the Futurex PKCS #11 library can locate its configuration file (fxpkcs11.cfg). Point it at the fxpkcs11.cfg you configured in Install and configure Futurex PKCS #11:
Shell
On Windows, set FXPKCS11_CFG as a machine-wide variable with setx instead (see Configure SunPKCS11 to use the Futurex PKCS11 module). If you set fxpkcs11.cfg in its default location, this step is not required.
2
Execute the following command, passing the pkcs11.cfg file you created in the previous section with -providerArg. Set -alias and -dname to a value that identifies this signing key:
Text
On Windows, run the same command in a Command Prompt window and replace /usr/local/etc/pkcs11.cfg with the path to your pkcs11.cfg file, such as C:\path\to\pkcs11.cfg.
This command uses RSA 3072, which is the key size Futurex validated for this integration and the minimum that current code signing certificate requirements expect. RSA 2048 also works with this flow if your signing policy calls for it.-sigalg SHA384withRSA sets the signature algorithm of the self-signed certificate that keytool creates alongside the key. It matches the SHA-384 digest the JSign examples use. It does not constrain the digest you pass to JSign later, so SHA256withRSA is also valid.The two -ext flags put the code signing extended key usage and the digitalSignature key usage on the generated certificate, which is what an Authenticode signing certificate requires.
All three provider flags are required and case-sensitive: -providerClass, -providerArg, and -providerName. If you misspell them or omit -providerName, SunPKCS11 falls back to generating the key in software and importing it, which defeats the purpose of the integration and fails on the CryptoHub.
The keytool application generates the key pair on the CryptoHub and self-signs a certificate for it. With no -storepass on the command line, keytool prompts for the KeyStore password.
3
When prompted for the KeyStore password, enter the CryptoHub identity password (PKCS #11 PIN) configured inside the <CRYPTO-OPR-PASS> tag in the fxpkcs11.cfg file.
Let keytool prompt for the PIN rather than passing -storepass on the command line. A PIN supplied as an argument is visible in your shell history and in the system process list.

Verify the key pair

Run the following keytool command to confirm the key pair generated on the CryptoHub and lists a PrivateKeyEntry:
Shell
The response is similar to the following:
Shell
The CryptoHub assigns the on-token key its own alias in the form <alias>-<id>:<alias> (for example, jsign-demo-1785267399:jsign-demo), where <id> is generated per key. This alias, not the short -alias value you passed to keytool -genkeypair, is what JSign and other tools must reference. The <id> value differs every time you generate a key, so you cannot predict it: copy the exact alias from this keytool -list output for the signing commands in JSign command examples.
The subject distinguished name is unaffected by the alias form. It comes from -dname, so CN=jsign-demo holds for any downstream check against the certificate subject.
If keytool -list reports 0 entries after a successful -genkeypair, the library is not pairing the certificate with the private key. Confirm you replaced the bundled FXPKCS11 4.59 library with 6.0 rev dc27 or later, and confirm both attributes(generate, ...) blocks are present in pkcs11.cfg.