RSA Certificate Manager (RCM)
Sun Solaris 2.8
SafeNet Luna SA 4.3.2
SafeNet Luna SA
Hardware Security Module (HSM)
RCM will not allow me to create a CA with SHA-256 in RSA for the SafeNet device.
With RSA Certificate Manager 6.8 build 514 and RSA Certificate Manager API can create keys on tokens. Luna CA3 supports key generation for varying key lengths in RSA and DSA key pairs.
RSA: 1024 bits, 2048 bits, 4096 bits
DSA: 512 bits, 1024 bits, 2048 bits
This is been added with with latest RCM Hot Fix, and it shows this in README:
****
Ability to support the SHA-2 algorithms using a PKCS #11 device
Prior to build 517, the SHA-2 algorithms using PKCS #11 device was not supported. Even if the PKCS #11 device supported the SHA-2 algorithms, these algorithms were not listed while creating the CA using Certificate Manager. As a result, Certificate Manager was unable to use the SHA-2 algorithms while creating the CA keys using PKCS #11 devices.
In RSA Certificate Manager 6.8 build517, this issue is fixed. Certificate Manager can now create the CA with SHA-256, SHA-384, or SHA-512 hash algorithms while using PKCS #11 devices.
****
Contact RSA Support and request RCM 6.8 build 517 hot fix.
Related Articles
Installing Validation Manager 3.0 fails when using an nCipher HSm. 3Number of Views KCA:Problem generating System CA key in SafeNet HSM during CM6.6 setup 2Number of Views Can the KCA OneStep SSL certificate private key be kept on a HSM? 10Number of Views Can I install RSA Key Recovery Manager without a hardware security module (HSM)? 14Number of Views When signing a SHA256 CA off a SHA1 Root CA it does not have a SHA256 signature algorithm in RCM 153Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service LDAP password authentication failed - Logon failure: unknown username or invalid password when attempting RADIUS authentic…