Key types and key generation
Use Key gen to define the key types that the template supports.
Allow only the key types that you want requesters to use. The CA issues a certificate only when the key pair, including the public key in the CSR or enrollment request, matches one of the key types defined in the template. If the key type doesn't match any configured type, the request fails.
You can also use Key gen to control server-side key pair generation. Set Enabled to False to prevent the CA from generating key pairs on behalf of requesters.
If you don't configure the Key gen, the template supports all key types and allows server-side key generation by default.
For ML-KEM, you can configure the following key types:
ML-KEM-512
ML-KEM-768
ML-KEM-1024
참고
Server-side key generation isn't supported for ML-KEM keys. The requester must provide the public key in the CSR or enrollment request.
JSON structure example
{
"key_gen": {
"enabled": true,
"key_type": {
"allowed_types": [
"rsa",
"ecdsa",
"Ed25519",
"MLDSA",
"SLHDSA",
"FNDSA",
"ML-KEM",
"MLDSA-44_RSA2048-Sha256",
"MLDSA-44_RSA2048-Sha256Pss",
"MLDSA-44_ECDSA-P256",
"MLDSA-44_Ed25519",
"MLDSA-65_RSA3072-Sha512",
"MLDSA-65_RSA3072-Sha512Pss",
"MLDSA-65_ECDSA-P256",
"MLDSA-65_Ed25519",
"MLDSA-87_ECDSA-P384"
],
"default_key_type":"rsa"
},
"rsa_key_size": {
"min_bits": 1024,
"max_bits": 4096,
"default_bits": 2048
},
"ecdsa_curve": {
"allowed_curves": [
"P-256",
"P-384",
"P-521"
],
"default_curve":"P-256"
},
"dilithium_key_size": {
"allowed_sizes": [
"MLDSA-44",
"MLDSA-65",
"MLDSA-87"
],
"default_size": "MLDSA-44"
},
"sphincs_key_size": {
"allowed_sizes": [
"SLHDSA-SHA2-128f",
"SLHDSA-SHA2-128s",
"SLHDSA-SHA2-192f",
"SLHDSA-SHA2-192s",
"SLHDSA-SHA2-256f",
"SLHDSA-SHA2-256s",
"SLHDSA-SHAKE-128f",
"SLHDSA-SHAKE-128s",
"SLHDSA-SHAKE-192f",
"SLHDSA-SHAKE-192s",
"SLHDSA-SHAKE-256f",
"SLHDSA-SHAKE-256s"
],
"default_size": "SLHDSA-SHA2-128f"
},
"falcon_key_size": {
"allowed_sizes": [
"FNDSA-512",
"FNDSA-1024"
],
"default_size": "FNDSA-512"
},
"mlkem_key_size": {
"allowed_sizes": [
"ML-KEM-512",
"ML-KEM-768",
"ML-KEM-1024"
],
"default_size": "ML-KEM-512"
}
}
}Parameters
Name | Type | Required/optional | Possible values |
|---|---|---|---|
| boolean | Optional (default is | When disabled, server-side key generation is also disabled |
| Object | Required | Defines the key types supported by this configuration |
| Array of strings | Required | Traditional key types::
Post-quantum key types:
Composite key types:
|
| String | Optional (default first value in | Specifies the default key type to use. The value must be one of the key types defined in |
| Object | Required | Specifies the RSA key sizes that can be used for key generation |
| Integer | Required | Specifies the minimum RSA key size, in bits. Supported values are:
|
| Integer | Required | Specifies the maximum RSA key size, in bits. Supported values are:
|
| Integer | Optional ( | Specifies the default RSA key size, in bits. The value must be one of the supported key sizes:
If no key size is specified, the value of |
| Object | Required | Specifies the ECDSA curves that can be used for key generation |
| Array of strings | Required | Lists the ECDSA curves that can be used for key generation. Supported values are:
|
..default_curve | String | Optional (first value in | Specifies the default ECDSA curve. The value must be one of the curves defined in |
| Object | Required | Specifies the MLDSA key sizes that can be used for key generation |
| Array of strings | Required | Specifies the MLDSA key sizes that can be used for key generation. Supported values are:
|
| String | Optional first value in | Specifies the default MLDSA key size. The value must be one of the sizes defined in |
| Object | Required | Specifies the SLHDSA key sizes that can be used for key generation |
| Array of strings | Required | Specifies the supported SLHDSA key sizes. Supported values are:
|
| String | Optional (first value in | Specifies the default SLHDSA key size. The value must be one of the sizes defined in |
| Object | Required | Specifies the FNDSA key sizes that can be used for key generation |
| Array of strings | Required | Lists the FNDSA key sizes that can be used for key generation. Supported values are:
|
| String | Optional (first value in | Specifies the default FNDSA key size. The value must be one of the sizes defined in |
| Object | Required | Defines the ML-KEM key sizes supported by this configuration. 참고Server-side key generation is not supported for ML-KEM. The requester must provide the public key in the CSR or enrollment request |
| Array of strings | Required | Specifies the supported ML-KEM key sizes. Supported values:
|
| String | Optional (first value in | Specifies the default ML-KEM key size. The value must be one of the sizes defined in |