Encryption Certificate

Infineon Security Platform

Infineon Security Platform Solution - User Initialization Wizard

Encryption Certificate

This page allows you to select an encryption certificate to be used for EFS and/or PSD. Such a certificate is identified by its thumbprint and is always assigned to an Infineon Security Platform User in an unambiguous form.

If no valid certificate is registered currently, but another suitable certificate is already available, the wizard offers to select this certificate automatically. If no such certificate is available, the wizard offers to create a new certificate and select it automatically.

If you do not want the wizard to automatically create and/or select a certificate, you can also do this manually.

The following table gives hints on how to use this wizard page.

Wizard Page Element Explanation
Current certificate Here you can find information on the encryption certificate currently registered (if you already had selected a certificate before).
New certificate Here you can find information on the encryption certificate which will be used in future (if another certificate than the current one is going to be used at all). This can be either a certificate which will be created and/or selected automatically by the wizard, or a certificate which you have manually created and/or selected via Change... button.
Change... Click this button to create and/or select an encryption certificate manually.
The Certificate Selection dialog will be displayed.

Rekeying for existing encrypted data: Please note that your old encryption certificate is still needed to decrypt your existing encrypted data. The rekeying process required to use the new certificate also for existing data depends on your operating system:
On operating systems which include the Microsoft Encrypting File System rekeying wizard (e.g. Windows 7 and Windows Vista), you need to perform the rekeying manually.
On all other operating systems, you need to use the command line tool "cipher.exe", or access the concerned files to have them automatically rekeyed.
More information is available in the Microsoft TechNet (search for "rekeying wizard" or "cipher.exe").

Key length for new certificates Here you can select the key length for newly created encryption certificates, e.g. 1024 bits or 2048 bits.


©Infineon Technologies AG