Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Supported key types for the PKCS #11 library for AWS CloudHSM Client SDK 5

Focus mode
Supported key types for the PKCS #11 library for AWS CloudHSM Client SDK 5 - AWS CloudHSM

The PKCS #11 library for AWS CloudHSM Client SDK 5supports the following key types.

Key Type Description
AES Generate 128, 192, and 256-bit AES keys.
Triple DES (3DES, DESede) Generate 192-bit Triple DES keys. See note 1 below for an upcoming change.
EC Generate keys with the secp224r1 (P-224), secp256r1 (P-256), secp256k1 (Blockchain), secp384r1 (P-384), and secp521r1 (P-521) curves.
GENERIC_SECRET Generate 1 to 800 bytes generic secrets.
RSA Generate 2048-bit to 4096-bit RSA keys, in increments of 256 bits.

[1] In accordance with NIST guidance, this is disallowed for clusters in FIPS mode after 2023. For clusters in non-FIPS mode, it is still allowed after 2023. See FIPS 140 Compliance: 2024 Mechanism Deprecation for details.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.