Managing PKA cryptographic keysEdit online Use these verbs to generate and manage PKA keys. PKA Key Generate (CSNDPKG)Use the PKA Key Generate verb to generate RSA, ECC, or PQC (ML-KEM, ML-DSA, CRYSTALS-Dilithium, CRYSTALS-Kyber) public-private key pairs for use with the appropriate algorithms.PKA Key Import (CSNDPKI)Use this service to import an RSA, ECC, a CRYSTALS-Dilithium, CRYSTALS-Kyber, ML-KEM or pure or pre-hash ML-DSA public-private key pair. A private key must be accompanied by the associated public key. The source PKA private-key either can be in the clear or it can be enciphered.PKA Key Token Build (CSNDPKB)Use this verb to build external PKA key tokens containing unenciphered private RSA, ECC, or PQC keys (an ML-KEM, ML-DSA, CRYSTALS-Dilithium, or CRYSTALS-Kyber key pair).PKA Key Token Change (CSNDKTC)The PKA Key Token Change verb changes PKA key tokens (RSA, ECC, or PQC) or trusted block key tokens from encipherment under the old ASYM or APKA master key to encipherment under the current ASYM or APKA master key.PKA Key Translate (CSNDPKT)Use the PKA Key Translate verb to translate an RSA key in a PKA key-token using an output format specified by the input rule array. The RSA key to be translated is provided in a source PKA key-token that contains a private-key section, and the translated key is returned in the buffer identified by the target_key_token parameter. If the source key is in an external key-token, the source transport key must be in an operational CCA or TR-31 DES key-token. PKA Public Key Extract (CSNDPKX)Use the PKA Public Key Extract verb to extract a PKA public key token from a supplied PKA internal or external private key token. Trusted Block Create (CSNDTBC)The verb creates an external trusted block under dual control. A trusted block is an extension of CCA PKA key tokens using new section identifiers.Public Infrastructure Certificate (CSNDPIC)Use the Public Infrastructure Certificate verb to create a self-signed PKCS #10 certificate signing request (CSR) based on an existing RSA or ECC pair of private key and public key. The self-signed PKCS #10 request for the input public key is signed by the input private key.Public Infrastructure Manage (CSNDPIM)Use the CSNDPIM verb to manage the public key infrastructure stored inside the adapter. Parent topic: CCA verbs