This page provides information on the PKCS#11 capabilities and restrictions that vault client users and developers need to consider when validating a CSP PKCS#11 Vault deployment.

General restrictions

By default, the server runs with Security Assurance Overrides set to None. With Release 10.6.1, you can only change the Security Assurance Overrides setting using the following REST API endpoint and not via the Cryptographic Security Platform Vault Management GUI.

/pkcs11/1.0/server/

Below is a list of general restrictions.

  • The client supports PKCS#11 3.2 functions with the restrictions described on this page.
  • Notification callbacks and asynchronous sessions are not supported.
  • Multipart encryption, decryption, signing, and verification operations are not supported.
  • All functions are forwarded to the nShield PKCS#11 Library, and all restrictions of that library apply.
  • Vendor-defined mechanisms are not supported by the CSP PKCS#11 client.
  • The client may filter mechanisms when it cannot serialize their parameters.
  • The mechanisms available in a deployment can differ from the mechanisms available in another HSM or firmware environment.

For information on the PKCS#11 3.2 specification, see:

https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.2/pkcs11-spec-v3.2.html

Supported functions

The following PKCS#11 3.2 functions are supported with the restrictions listed below. Functions and options not supported by the nShield library will return its error code.

Function

Restriction

C_DecryptInit


C_Decrypt


C_EncryptInit


C_Encrypt


C_Initialize

Mutex function pointers are ignored

C_Finalize


C_GetInfo


C_GetFunctionList


C_GetInterfaceList


C_GetInterface


C_GenerateKey


C_GenerateKeyPair


C_WrapKey


C_UnwrapKey


C_DeriveKey


C_EncapsulateKey


C_DecapsulateKey


C_DigestInit


C_Digest


C_DigestUpdate


C_DigestFinal


C_CreateObject


C_CopyObject


C_DestroyObject


C_GetObjectSize


C_GetAttributeValue


C_SetAttributeValue


C_FindObjectsInit


C_FindObjects


C_FindObjectsFinal


C_GenerateRandom


C_OpenSession

Notification callbacks and CKF_ASYNC_SESSION are not supported; CKF_SERIAL_SESSION is required.

C_CloseSession


C_CloseAllSessions


C_GetSessionInfo


C_Login


C_Logout


C_LoginUser


C_SignInit


C_Sign


C_GetSlotList


C_GetSlotInfo


C_GetTokenInfo


C_GetMechanismList


C_GetMechanismInfo


C_VerifyInit


C_Verify


Mechanisms

The available mechanisms depend on the connected nShield HSM and its firmware. The CSP PKCS#11 client also filters mechanisms that it cannot serialize safely. Do not use a mechanism solely because it is defined by the PKCS#11 standard or appears on another HSM.

  • Use the PKCS#11 slot and mechanism information functions to confirm availability in the deployed environment. The nShield PKCS#11 mechanism restrictions documented by Entrust also apply.
  • For an application-specific compatibility assessment, check the mechanisms returned by C_GetMechanismList and that the required functions are in the list above.