This page provides information on the PKCS#11 capabilities and restrictions that vault client users and developers need to consider when validating a CSP PKCS#11 Vault deployment.
General restrictions
By default, the server runs with Security Assurance Overrides set to None. With Release 10.6.1, you can only change the Security Assurance Overrides setting using the following REST API endpoint and not via the Cryptographic Security Platform Vault Management GUI.
/pkcs11/1.0/server/ Below is a list of general restrictions.
- The client supports PKCS#11 3.2 functions with the restrictions described on this page.
- Notification callbacks and asynchronous sessions are not supported.
- Multipart encryption, decryption, signing, and verification operations are not supported.
- All functions are forwarded to the nShield PKCS#11 Library, and all restrictions of that library apply.
- Vendor-defined mechanisms are not supported by the CSP PKCS#11 client.
- The client may filter mechanisms when it cannot serialize their parameters.
- The mechanisms available in a deployment can differ from the mechanisms available in another HSM or firmware environment.
For information on the PKCS#11 3.2 specification, see:
https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.2/pkcs11-spec-v3.2.html
Supported functions
The following PKCS#11 3.2 functions are supported with the restrictions listed below. Functions and options not supported by the nShield library will return its error code.
Function | Restriction |
|---|---|
C_DecryptInit | |
C_Decrypt | |
C_EncryptInit | |
C_Encrypt | |
C_Initialize | Mutex function pointers are ignored |
C_Finalize | |
C_GetInfo | |
C_GetFunctionList | |
C_GetInterfaceList | |
C_GetInterface | |
C_GenerateKey | |
C_GenerateKeyPair | |
C_WrapKey | |
C_UnwrapKey | |
C_DeriveKey | |
C_EncapsulateKey | |
C_DecapsulateKey | |
C_DigestInit | |
C_Digest | |
C_DigestUpdate | |
C_DigestFinal | |
C_CreateObject | |
C_CopyObject | |
C_DestroyObject | |
C_GetObjectSize | |
C_GetAttributeValue | |
C_SetAttributeValue | |
C_FindObjectsInit | |
C_FindObjects | |
C_FindObjectsFinal | |
C_GenerateRandom | |
C_OpenSession | Notification callbacks and CKF_ASYNC_SESSION are not supported; CKF_SERIAL_SESSION is required. |
C_CloseSession | |
C_CloseAllSessions | |
C_GetSessionInfo | |
C_Login | |
C_Logout | |
C_LoginUser | |
C_SignInit | |
C_Sign | |
C_GetSlotList | |
C_GetSlotInfo | |
C_GetTokenInfo | |
C_GetMechanismList | |
C_GetMechanismInfo | |
C_VerifyInit | |
C_Verify |
Mechanisms
The available mechanisms depend on the connected nShield HSM and its firmware. The CSP PKCS#11 client also filters mechanisms that it cannot serialize safely. Do not use a mechanism solely because it is defined by the PKCS#11 standard or appears on another HSM.
- Use the PKCS#11 slot and mechanism information functions to confirm availability in the deployed environment. The nShield PKCS#11 mechanism restrictions documented by Entrust also apply.
- For an application-specific compatibility assessment, check the mechanisms returned by
C_GetMechanismListand that the required functions are in the list above.