CKM_DH_PKCS_DERIVE
Supported Operations
Encrypt and Decrypt | No |
Sign and Verify | Yes |
SignRecover and VerifyRecover | No |
Digest | No |
Generate Key/Key-Pair | No |
Wrap and Unwrap | No |
Derive | No |
Available in FIPS Mode | Yes |
Restrictions in FIPS Mode | Minimum 2048-bit modulus for all operations Cannot be used for existing Diffie-Hellman keys smaller than 2048 bits |
Key Size Range (bits) and Parameters
Minimum | 512 |
FIPS Minimum | 2048 |
Maximum | 4096 |
Parameter | Bytes (Big Integer) |
Description
For a full description of this mechanism, refer to the PKCS#11 version 2.20 documentation from RSA Laboratories.
Return to SafeNet ProtectToolkit-C Mechanisms