This page is used to configure the Certificate Generation Settings that will be generated in the Go>Sign Desktop.



The configuration items are as follows:


Items

Description

Key Algorithm

Specify the Key Algorithm that will be used to generate the key pair from Go>Sign Desktop.

  • RSA
  • ECDSA
  • ML-DSA


Note: Keep below points in mind while using ML-DSA key algorithm: 

  • The keys generated using PQC algorithm, i.e. ML-DSA, are created solely through software and not via HSMs.
  • The ML-DSA algorithm will be only be used for document signing purposes.
  • The below mentioned signature types are supported for ML-DSA:
    • PKCS1
    • CMS
    • CAdES Baseline
    • CAdES Extended
  • The ML-DSA key algorithm will only be available to the user when the Keystore Settings are set to 'Roaming Key' for the Go>Sign Profile.


     

Currently the PQC algorithm (ML-DSA) is only for proof of concept (POC).

Curve Type

Select the Curve Type that will be used to generate the key pair from Go>Sign Desktop. ADSS Server supports the following Curve Types:

  • NIST P
  • SEC2 K
  • Brainpool R
  • Brainpool T


Note: The Curve Type drop-down will be available only when ECDSA algorithm is selected in key algorithm field.

Key Length

Specify the Key Length against the above selected algorithm. 

  • The choices of RSA keys are:
    • 1024
    • 2048
    • 3072
    • 4096
  • The choices for ECDSA keys are: 
    • 160
    • 192
    • 224
    • 256
    • 320
    • 384
    • 512
    • 521

Security Level

The Security Level drop-down will be available when ML-DSA is selected in the 'Key Algorithm' field. This drop-down allows the user to choose the security level for the selected key algorithm. The security levels for ML-DSA are defined below:

  • 2
  • 3
  • 5

Password Strength

Specify the strength of password by providing a desired regular expression. 

See the following link to check some example of regular expressions:
http://www.mkyong.com/regular-expressions/10-java-regular-expression-examples-you-should-know/


Clicking the Next icon will display the Key Store Settings page.

See also

Certificate Generation Settings
Key Store Settings
Service Settings

Advanced Settings