Exporting a key by using the graphical user interface

You can export symmetric and private keys to an encrypted keystore file on an IBM® Security Guardium® Key Lifecycle Manager server. You can then import the keys from this file into another IBM Security Guardium Key Lifecycle Manager server to enable data transfer between these servers.

Procedure

  1. Go to the appropriate page or directory.
    1. Log on to the graphical user interface.
    2. From the main menu, click Search.
    3. In the left Search pane, in Objects Type, select Symmetric Key or Private Key, depending on which keys you want to search. Alternatively, you can also search for device groups whose keys you want to export.
    4. Click Search.
      The keys of selected key type are listed in the right pane.
  2. Export the keys to a keystore file.
    1. From the list of keys in the right pane, select the keys that you want to export (Use CTRL to select multiple keys), and click Export.
    2. In the Export Symmetric Keys or Export Private Keys window, specify a name for the keystore file that is used to store the exported keys.
    3. Optional: Specify a different file location to save the keystore file. By default, the File location field displays the default SKLM_DATA directory path, where the keystore file is saved.
      For example, C:\Program Files\IBM\WebSphere\Liberty\products\sklm\data.
      For the definition of SKLM_DATA, see Definitions for HOME and other directory variables.
    4. For symmetric key type: Specify a certificate as the key alias. The Certificate is the public key entry in the keystore that is used to encrypt the symmetric keys. Only the holder of the corresponding private key can access the keys.
    5. For private key type: Create an encryption password.
      This password will be used to decrypt the keystore file while importing the keys into an IBM Security Guardium Key Lifecycle Manager server.
    6. Click Export.

What to do next

Import the keys into the IBM Security Guardium Key Lifecycle Manager server with which you want to enable data transfer.