AES key export functionality #92
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Currently, the Pico HSM supports AES key generation, encryption, and decryption. However, the generated AES keys are set to be "never extractable" by default, which restricts the flexibility of using these keys in certain scenarios. For example, in a backup or key migration process, it is necessary to export the AES keys securely.
if you enable dkek the aes key can export a wky file
As said, keys are wrapped with the DKEK.