aws-samples / aws-samples/aws-cloudhsm-jce-examples

Why the AWS local keystore file has symmetric and asymmetric keys?

Open
#66 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
46
Forks
70
Avg merge
52m
Merged PRs (30d)
4

Description

I generated a keypair in Cloud HSM by giving a keystore file.
I downloaded the keystore file and opened it in keystore explorer and I see symmetric and asymmetric key entries. As per AWS documentation, only the certificate corresponding to keypair is stored in the local keystore file.

I exported the private key but it is not complete.
As the expected public is exportable and complete.

I assume, Cloud HSM maintains a reference to all the entries with partial key info. Is it correct?

**Generate keypair with a certificate with store file**
```
keytool -genkeypair -alias alias1 -keystore /home/user/my_cloudhsm/my-cloudhsm.store "CN=alias1.example.com, OU=Research, O=Acme, L=XYZ, ST=CA, C=US" -storetype CLOUDHSM -storepass password -keyalg rsa -keysize 2048 -sigalg sha512withrsa -validity 360 -dname -J-classpath '-J/opt/cloudhsm/java/*' -J-Djava.library.path=/opt/cloudhsm/lib
```

Contributor guide

Open the contributing guide

Research direction

The issue provides a keytool command using the CLOUDHSM keystore type but names no repository file or test. Start by reviewing the AWS CloudHSM keystore and key-export documentation, then reproduce the command if the required environment is available. Done means documenting whether the symmetric and asymmetric entries and incomplete private-key export are expected.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, java
Domain
cloud, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.