CSP Vault for PKCS#11 provides a PKCS#11 interface for applications that use keys and cryptographic operations managed by a CSP Vault and backed by an nShield HSM. The client communicates securely with the Vault server using mutual TLS (mTLS).
- PKCS#11 is a public standard that defines an API for interacting with hardware security modules (HSMs). CSP Vault for PKCS#11 includes a lightweight client that communicates with the nShield HSMs used by the CSP Vault cluster. The PKCS#11 client implements https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.2/pkcs11-spec-v3.2.html
- CSP Vault includes a PKCS#11 server that listens for secure client connections. Client libraries are available for Linux and Windows on x86-64 platforms. The client establishes a mutually authenticated TLS (mTLS) connection to the PKCS#11 server and must use a client certificate issued by CSP Vault.
- The client serializes PKCS#11 function calls and their parameters and sends them to the PKCS#11 server running in the CSP Vault cluster. The server passes the requests to the nShield
libcknfast.solibrary, which communicates with the HSMs and returns the results to the client. See https://nshielddocs.entrust.com/security-world-docs/api-pkcs11/intro.html for details. - Release 10.6.1 supports module protection and softcard protection. Data used by CSP Vault for PKCS#11 is isolated from data used by other CSP Vault service.
See below for the configuration steps.