Create an Encryption Key
The following procedure is based on CipherTrust Manager version 2.2. If you are using a different version, see the CipherTrust Manager documentation for the version that you are using.
-
From the Products page in the CipherTrust Manager Console, click Keys in the left hand pane.
To navigate to the Products page from anywhere in the CipherTrust Manager Console, click the App Switcher icon in the top left corner.
-
Above the Key table, click Create a New Key.
-
In the Key Name field, add a name for the key. This name must be unique. For example, Simple-Key.
-
In the Key Usage section, make sure Encrypt and Decrypt are selected.
-
Click Create. CipherTrust Manager displays the properties for the new key.
-
In the general options area, enable the Exportable option.
You can also enable the Deletable option in this section if you want a CipherTrust Manager Administrator to be able to delete the key.
-
In the Key Access section, do the following:
a. In the Search Groups box, type CTE.
If no groups display, make sure that the Added Only option is disabled.
b. Click the Read and Export option for both the CTE Admins and CTE Clients groups.
c. When you are done, click Update.
-
Click the CTE tab and set the following properties:
-
CTE Versioned: Specify whether the key is versioned. By default, the key is set as versioned.
For a standard policy, you should clear this check box. If you do not, the key will not appear in the keys list when you add the key rule to the standard policy.
-
Persistent on Client: Specify whether the key is stored in persistent memory on the client.
When the check box is selected, the key is downloaded and stored (in an encrypted form) in persistent memory on the client.
When the check box is left clear, the key is downloaded to non-persistent memory on the client. Every time the key is needed, the client retrieves it from the CipherTrust Manager. This is the default setting.
-
Encryption Mode: Encryption mode of the key. The options are:
-
CBC
-
CBC CS1
-
XTS
Encryption using the XTS and CBC CS1 keys is known as enhanced encryption. For details, see the CTE Agent for Linux Advanced Configuration and Integration Guide.
-
When you are done, click Update.
-