KMIP vaults can be configured with a Key Encryption Key (KEK) that provides an extra layer of security by encrypting individual KMIP objects.
When KEK wrapping is enabled, the KMIP object data is protected not only by Cryptographic Security Platform Vault object store encryption but also by a KEK stored in an HSM. KMIP vaults can use the system HSM configured on Cryptographic Security Platform Vault to generate and store KEK.
The system HSM server configuration is shared by all Cryptographic Security Platform Vault for KMIPs.
To configure KEK
- Log in to the Cryptographic Security Platform Vault for KMIP web GUI.
- Click the gear icon in the top-right corner to view Settings.
- On the Settings page, click HSM.
In the KMIP Key Wrapping window, select the options you want.
- When you are finished, click Enable.
The Cryptographic Security Platform Vault contacts the HSM to create a root key specified by the root key label (if it doesn’t already exist) and uses it to derive a KEK. The system then encrypts each KMIP object with a unique key derived from the KEK. The system encrypts all existing KMIP objects in the background and generates an audit log.
To disable KEK wrapping, set the status button to Disabled. The system decrypts all existing KMIP objects in the background and generates an audit log.
Server
Select System HSM. This allows you to use the HSM configured to work with KeyControl. This can be either the Luna SA HSM, Luna Cloud HSM, or nShield Connect HSM. You must configure the HSM before it will display here.
HSM Root Key Label
The identifier used to identify the root key on the HSM that is used to wrap and unwrap keys. If the root key label already exists, it will be used. If it does not exist, Cryptographic Security Platform Vault creates a new one.
The root key label must meet the following requirements:
At least 8 characters
No more than 31 characters
Can include uppercase, lowercase, numbers, and special characters
No space or tab characters
At this point, all existing KMIP objects and all new Key creation requests will be encrypted using the key.
KEK Cache Timeout
For KMIP Key wrapping, this is the cache timeout for the KEK. Because frequently connecting to the System HSM to fetch the KEK and encrypt the object can affect performance, you can choose how long to keep the KEK cached in Cryptographic Security Platform Vault. When the timeout period ends, the Cryptographic Security Platform Vault deletes the KEK from its cache. The default value is 30 minutes. Set 0 to disable KEK cache timeout.