Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Supported key types for PKCS #11 library for AWS CloudHSM Client SDK 3

Focus mode
Supported key types for PKCS #11 library for AWS CloudHSM Client SDK 3 - AWS CloudHSM

The PKCS #11 library supports the following key types with AWS CloudHSM Client SDK 3.

Key Type Description
RSA Generate 2048-bit to 4096-bit RSA keys, in increments of 256 bits.
EC Generate keys with the secp224r1 (P-224), secp256r1 (P-256), secp256k1 (Blockchain), secp384r1 (P-384), and secp521r1 (P-521) curves.
AES Generate 128, 192, and 256-bit AES keys.
DES3 (Triple DES) Generate 192-bit DES3 keys. See note 1 below for an upcoming change.
GENERIC_SECRET Generate 1 to 64 bytes generic secrets.
PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.