McAfee MEJCAE-AM-DA Product Guide - Page 21

DH/DSS, RSA Legacy, RSAv4, Viewing your keys

Page 21 highlights

Creating and Exchanging Keys Creating a key pair • Enter 1, the default option, to create a DH/DSS key. • Enter 2 to create an RSA key. • Enter 3 to create an RSA Legacy key. Note: RSA Legacy keys do not support subkeys. 3 Select the size you want the key to be. A larger key size may take a long time to generate, depending on the speed of the computer you are using. Note: For DH/DSS key pairs, the signing key can only be 1024 bits, so the size you enter applies to the encryption subkey. For RSA v4 key pairs, the size you enter applies to both the signing key and the encryption subkey. For RSA Legacy keys, only one key is used for both signing and encryption, so the size you enter applies to that key. The key size corresponds to the number of bits used to construct your digital key. A larger key is stronger. However, when you use a larger key, it takes more time to encrypt and decrypt. You need to strike a balance between the convenience of performing E-Business Server functions quickly with a smaller key and the increased level of security provided by a larger key. Unless you are exchanging extremely sensitive information that is of enough interest that someone would be willing to mount an expensive and time-consuming cryptographic attack in order to read it, you are safe using a key composed of 1024 bits. For a DH/DSS key or a new RSAv4 key: • Enter 1 to create a key of 1024 bits. • Enter 2 to create a key of 2048 bits. • Enter 3 to create a key of 3072 bits. • Enter any key size you want between 1024 bits and 4096 bits. For an RSA Legacy key: • Enter 1 to select a key size of 1024 bits. • Enter 2 to select a key size of 2048 bits. • Enter any key size you want between 1024 bits and 2048 bits. 4 Enter the text that will comprise your user ID (149 characters, maximum). E-Business Server prompts you with instructions. It's not absolutely necessary to enter your real name or even your email address. However, using your real name makes it easier for others to identify you as the owner of your public key. For example: Robert M. Huang If you do not have an email address, use your phone number or some other unique information that would help ensure that your user ID is unique. Note: Do not create a user ID that starts with a dash. You cannot specify a user ID that starts with a dash in key commands. 5 Enter a passphrase, a string of characters or words you want to use to maintain exclusive access to your private key. Note: For more information on creating an effective passphrase, see Creating a passphrase that you will remember on page 21. 6 When prompted, enter the same passphrase again for confirmation. 7 If prompted, enter random text to help the E-Business Server software accumulate some random bits to create your keys. Enter keystrokes that are reasonably random in their timing. The generated key pair is placed on your public and private keyrings. To view your new key pair, use the --key-list option. For more information see, Viewing your keys on page 28. 19 E-Business Server™ 8.6 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

19
E-Business Server
8.6
Product Guide
Creating and Exchanging Keys
Creating a key pair
• Enter
1
,
the default option,
to create a
DH/DSS
key.
• Enter
2
to create an
RSA
key.
• Enter
3
to create an
RSA Legacy
key.
Note:
RSA Legacy keys do not support subkeys.
3
Select the size you want the key to be. A larger key size may take a long time to generate, depending on
the speed of the computer you are using.
Note:
For DH/DSS key pairs, the signing key can only be 1024 bits, so the size you enter applies to the encryption subkey.
For RSA v4 key pairs, the size you enter applies to both the signing key and the encryption subkey. For RSA Legacy keys,
only one key is used for both signing and encryption, so the size you enter applies to that key.
The key size corresponds to the number of bits used to construct your digital key. A larger key is
stronger. However, when you use a larger key, it takes more time to encrypt and decrypt. You need to
strike a balance between the convenience of performing E-Business Server functions quickly with a
smaller key and the increased level of security provided by a larger key.
Unless you are exchanging extremely sensitive information that is of enough interest that someone
would be willing to mount an expensive and time-consuming cryptographic attack in order to read it,
you are safe using a key composed of 1024 bits.
For a
DH/DSS
key or a new
RSAv4
key:
• Enter
1
to create a key of 1024 bits.
• Enter
2
to create a key of 2048 bits.
• Enter
3
to create a key of 3072 bits.
Enter any key size you want between 1024 bits and 4096 bits.
For an
RSA Legacy
key:
• Enter
1
to select a key size of 1024 bits.
• Enter
2
to select a key size of 2048 bits.
Enter any key size you want between 1024 bits and 2048 bits.
4
Enter the text that will comprise your user ID (149 characters, maximum). E-Business Server prompts
you with instructions. It’s not absolutely necessary to enter your real name or even your email address.
However, using your real name makes it easier for others to identify you as the owner of your public key.
For example:
Robert M. Huang <[email protected]>
If you do not have an email address, use your phone number or some other unique information that
would help ensure that your user ID is unique.
Note:
Do not create a user ID that starts with a dash. You cannot specify a user ID that starts with a dash in key
commands.
5
Enter a passphrase, a string of characters or words you want to use to maintain exclusive access to your
private key.
Note:
For more information on creating an effective passphrase, see
Creating a passphrase that you will remember
on
page 21
.
6
When prompted, enter the same passphrase again for confirmation.
7
If prompted, enter random text to help the E-Business Server software accumulate some random bits to
create your keys. Enter keystrokes that are reasonably random in their timing.
The generated key pair is placed on your public and private keyrings.
To view your new key pair, use the
--key-list
option. For more information see,
Viewing your keys
on
page 28
.