Perform the following tasks to generate an RSA key pair on the KMES Series 3:
You must generate the Bitwarden key pair under a root CA certificate to give it the encrypt and decrypt security usage it requires.
Create X.509 certificate container
Perform the following steps to create X.509 certificate container and root CA:
Go to PKI > Certificate Authorities.
In the X.509 Certificate Container creation dialog, configure the following settings:
- Name: Bitwarden
- Host: None
- Type: X.509
- Owner group: Select the Bitwarden role
Right-click the Bitwarden X.509 certificate container and select Add Certificate > New Certificate.
Configure the following Subject DN settings:
- Preset: Classic
- Common Name: Root
Configure the following Basic Info settings:
- Leave set the default values.
Configure the following V3 Extensions settings:
- Profile: Certificate Authority
Generate Bitwarden key pair
Perform the following steps to generate Bitwarden key pair:
Right-click the Root CA certificate and select Add Certificate > New Certificate.
Configure the following Subject DN settings:
- Preset: Classic
- Common Name: Bitwarden
Configure the following Basic Info settings:
- Security Usage: Encrypt/Decrypt
- Leave all other fields set to the default values.
Configure the following V3 Extensions settings:
- Profile: TLS Client Certificate
Export Bitwarden certificate
Perform the following steps to export Bitwarden certificate:
Right-click the Bitwarden certificate and select Export > Certificate(s).
Change Encoding to PEM and select [ Browse ].
Specify a filename for web transfer (such as Bitwarden-Cert.pem) and select [ OK ].
Select [ OK ] to initiate the export.
Save the certificate file when your browser prompts you.
Assign a name to the key
Perform the following steps to assign a name to the private key:
Go to Key Management > Keys.
Right-click the Bitwarden key pair in the Keys section and select Edit.
Under Key Settings, enter Bitwarden in the Name field and select [ OK ] to save.
Grant Use permission
Perform the following steps to grant Use permission on the private key:
Go to Administrative Services > Key Management > Key Database.
Right-click the Bitwarden key pair and select Permission.
Select the Bitwarden role in the drop-down menu and select [ Add ].
Select the Permission drop-down option next to the Bitwarden role and select Use.