Skip to main content

Key types and key generation

Use Key gen to define the key types that the template supports.

Allow only the key types that you want requesters to use. The CA issues a certificate only when the key pair, including the public key in the CSR or enrollment request, matches one of the key types defined in the template. If the key type doesn't match any configured type, the request fails.

You can also use Key gen to control server-side key pair generation. Set Enabled to False to prevent the CA from generating key pairs on behalf of requesters.

If you don't configure the Key gen, the template supports all key types and allows server-side key generation by default.

For ML-KEM, you can configure the following key types:

  • ML-KEM-512

  • ML-KEM-768

  • ML-KEM-1024

참고

Server-side key generation isn't supported for ML-KEM keys. The requester must provide the public key in the CSR or enrollment request.

JSON structure example

{
  "key_gen": {
    "enabled": true,
    "key_type": {
      "allowed_types": [
        "rsa",
        "ecdsa",
        "Ed25519",
        "MLDSA",
        "SLHDSA",
        "FNDSA",
        "ML-KEM",
        "MLDSA-44_RSA2048-Sha256",
        "MLDSA-44_RSA2048-Sha256Pss",
        "MLDSA-44_ECDSA-P256",
        "MLDSA-44_Ed25519",
        "MLDSA-65_RSA3072-Sha512",
        "MLDSA-65_RSA3072-Sha512Pss",
        "MLDSA-65_ECDSA-P256",
        "MLDSA-65_Ed25519",
        "MLDSA-87_ECDSA-P384"
      ],
      "default_key_type":"rsa"
    },
    "rsa_key_size": {
      "min_bits": 1024,
      "max_bits": 4096,
      "default_bits": 2048
    },
    "ecdsa_curve": {
      "allowed_curves": [
        "P-256",
        "P-384",
        "P-521"
      ],
      "default_curve":"P-256"
    },
    "dilithium_key_size": {
      "allowed_sizes": [
        "MLDSA-44",
        "MLDSA-65",
        "MLDSA-87"
      ],
      "default_size": "MLDSA-44"
    },
    "sphincs_key_size": {
      "allowed_sizes": [
        "SLHDSA-SHA2-128f",
        "SLHDSA-SHA2-128s",
        "SLHDSA-SHA2-192f",
        "SLHDSA-SHA2-192s",
        "SLHDSA-SHA2-256f",
        "SLHDSA-SHA2-256s",
        "SLHDSA-SHAKE-128f",
        "SLHDSA-SHAKE-128s",
        "SLHDSA-SHAKE-192f",
        "SLHDSA-SHAKE-192s",
        "SLHDSA-SHAKE-256f",
        "SLHDSA-SHAKE-256s"
      ],
      "default_size": "SLHDSA-SHA2-128f"
    },
    "falcon_key_size": {
      "allowed_sizes": [
        "FNDSA-512",
        "FNDSA-1024"
      ],
      "default_size": "FNDSA-512"
    },
    "mlkem_key_size": {
      "allowed_sizes": [
        "ML-KEM-512",
        "ML-KEM-768",
        "ML-KEM-1024"
      ],
      "default_size": "ML-KEM-512"
    }
  }
}

Parameters

표 1. Parameters - Key types and key generation

Name

Type

Required/optional

Possible values

enabled

boolean

Optional (default is true)

When disabled, server-side key generation is also disabled

key_type

Object

Required

Defines the key types supported by this configuration

..allowed_types

Array of strings

Required

Traditional key types::

  • rsa

  • ecdsa

  • Ed25519

Post-quantum key types:

  • MLDSA

  • SLHDSA

  • FNDSA

  • ML-KEM

Composite key types:

  • MLDSA-44_RSA2048-Sha256

  • MLDSA-44_RSA2048-Sha256Pss

  • MLDSA-44_ECDSA-P256

  • MLDSA-44_Ed25519

  • MLDSA-65_RSA3072-Sha512

  • MLDSA-65_RSA3072-Sha512Pss

  • MLDSA-65_ECDSA-P256

  • MLDSA-65_Ed25519

  • MLDSA-87_ECDSA-P384

..default_key_type

String

Optional (default first value in allowed_types

Specifies the default key type to use. The value must be one of the key types defined in allowed_types

rsa_key_size

Object

Required

Specifies the RSA key sizes that can be used for key generation

..min_bits

Integer

Required

Specifies the minimum RSA key size, in bits. Supported values are:

  • 1024

  • 2048

  • 3078

  • 4096

..max_bits

Integer

Required

Specifies the maximum RSA key size, in bits. Supported values are:

  • 1024

  • 2048

  • 3078

  • 4096

..default_bits

Integer

Optional (min bits ) will be used as default

Specifies the default RSA key size, in bits. The value must be one of the supported key sizes:

  • 1024

  • 2048

  • 3078

  • 4096

If no key size is specified, the value of min_bits is used

ecdsa_curve

Object

Required

Specifies the ECDSA curves that can be used for key generation

..allowed_curver

Array of strings

Required

Lists the ECDSA curves that can be used for key generation. Supported values are:

  • P-256

  • P-384

  • P-521

..default_curve

String

Optional (first value in allowed_curves will be used as default

Specifies the default ECDSA curve. The value must be one of the curves defined in allowed_curves

dilithium_key_size

Object

Required

Specifies the MLDSA key sizes that can be used for key generation

..allowed_sizes

Array of strings

Required

Specifies the MLDSA key sizes that can be used for key generation. Supported values are:

  • MLDSA-44

  • MLDSA-65

  • MLDSA-87

..default_size

String

Optional first value in ..allowed_sizeswill be used as default

Specifies the default MLDSA key size. The value must be one of the sizes defined in allowed_sizes

sphincs_key_size

Object

Required

Specifies the SLHDSA key sizes that can be used for key generation

..allowed_sizes

Array of strings

Required

Specifies the supported SLHDSA key sizes. Supported values are:

  • SLHDSA-SHA2-128f

  • SLHDSA-SHA2-128s

  • SLHDSA-SHA2-192f

  • SLHDSA-SHA2-192s

  • SLHDSA-SHA2-256f

  • SLHDSA-SHA2-256s

  • SLHDSA-SHAKE-128f

  • SLHDSA-SHAKE-128s

  • SLHDSA-SHAKE-192f

  • SLHDSA-SHAKE-192s

  • SLHDSA-SHAKE-256f

  • SLHDSA-SHAKE-256s

..default_size

String

Optional (first value in allowed_sizeswill be used as default)

Specifies the default SLHDSA key size. The value must be one of the sizes defined in allowed_sizes

falcon_key_size

Object

Required

Specifies the FNDSA key sizes that can be used for key generation

..allowed_sizes

Array of strings

Required

Lists the FNDSA key sizes that can be used for key generation. Supported values are:

  • FNDSA-512

  • FNDSA-1024

..default_size

String

Optional (first value in allowed_sizeswill be used as default)

Specifies the default FNDSA key size. The value must be one of the sizes defined in allowed_sizes

mlkem_key_size

Object

Required

Defines the ML-KEM key sizes supported by this configuration.

참고

Server-side key generation is not supported for ML-KEM. The requester must provide the public key in the CSR or enrollment request

..allowed_sizes

Array of strings

Required

Specifies the supported ML-KEM key sizes. Supported values:

  • ML-KEM-512

  • ML-KEM-768

  • ML-KEM-1024

..default_size

String

Optional (first value in allowed_sizes will be used as default

Specifies the default ML-KEM key size. The value must be one of the sizes defined in allowed_sizes