Skip to content

Export private key #5

Answered by polhenarejos
kamilgrzela asked this question in Q&A
Discussion options

You must be logged in to vote

You have two ways of exporting:

  • PKCS12 format is used, for instance, to perform S/MIME signing. Most of email clients accept PKCS12 cert+privkey file formats. In this case, the private key is protected with a passphrase you provide.
  • Wrap/unwrap is used to backup your private keys. It is useful to export them to another device or just for having a backup in case your device suddenly deads. In this approach, the private key is wrapped by using a device key, usually generated from multiple shares custodied by different people.

Besides of that, you can mark a key as non-extractable and, therefore, impossible to backup.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by kamilgrzela
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants