About this guide
About Cryptographic Security Platform
About Vault appliance
Major Components
Entrust Hardened OS
CSP Vault Clusters
About Entrust Policy Agent
Encryption Key Sizes and Algorithms
Secure File Migration
Administrative Model
Administrative Interfaces
CSP Vault Management web GUI Overview
CSP Vault System Console Overview
Entrust Policy Agent GUI Overview
Release notes
Release notes for 10.1
Release notes for 10.0
Release notes for 10.1.1
Release notes for 10.2
Release notes for 10.3.1
Release notes for 10.4.1
Release notes for 10.4.1.1
Release notes for 10.4.3
Release notes for 10.4.5
Release notes for 10.4.7
Release notes for 10.5.1
Release notes for 10.5.3
Release notes for 10.6.1
Upgrading to 10.6.1
Changes in 10.6.1
Fixed in 10.6.1
Vault issues in 10.6.1
Windows-specific Policy Agent issues in 10.6.1
Linux-specific Policy Agent issues in 10.6.1
Requirements
System resources
Network requirements
Browser requirements
Platform requirements
Installing CSP Vault
Installation Overview
CSP Vault OVA Installation
OVA installation overview
Installing CSP Vault from an OVA Template
Configuring the First CSP Vault Node (OVA Install)
Adding a New CSP Vault Node to an Existing Cluster (OVA Install)
CSP Vault ISO Installation for Hypervisor
ISO Installation Overview
Installing the First CSP Vault Node from an ISO Image
Installing an Additional CSP Vault Cluster Node from an ISO Image
CSP Vault ISO Installation for Bare Metal Server
ISO Installation Overview for Bare Metal Server
Prerequisites and Requirements for Installing CSP Vault on a Bare Metal Server
Installing the First CSP Vault Node on a Bare Metal Server from an ISO
Installing an Additional CSP Vault Node on a Bare Metal Server from an ISO
CSP Vault in Amazon Web Services
AWS Deployment Overview
Deploying the First CSP Vault Node in AWS
Associating an Elastic IP Address with the CSP Vault Instance
Configuring the First CSP Vault Node in AWS
Deploying Additional CSP Vault Nodes in AWS
Configuring Additional CSP Vault Nodes in AWS
CSP Vault in Google Cloud Platform
GCP Deployment Overview
Deploying the First CSP Vault Node in GCP
Configuring Firewall Rules for the CSP Vault Instance
Configuring the First GCP Node
Configuring Additional GCP Nodes
CSP Vault in Microsoft Azure
Azure Deployment Overview
Recommendations
Deploying a CSP Vault Node in Azure
Configuring the First CSP Vault Node in Azure
Configuring Additional CSP Vault Nodes in Azure
Initializing the web GUI
User guide
CSP Vault authentication and user accounts
Authentication for CSP Vault User Accounts
Configuring local authentication
Configuring Local Authentication Settings
Configuring Active Directory
Adding an Active Directory Group
Configuring OIDC
Specifying an LDAP/AD Authentication Server
Specifying an OpenLDAP Authentication Server
Configuring OIDC with Active Directory for CSP Vault
Configuring OIDC for Vault
Configuring an OpenID Connect Provider
Setting the CSP Vault Management webGUI Session Timeout
Setting the Default Account Expiration
Creating a New CSP Vault-Managed User Account
Setting webGUI User Preferences
Changing Your CSP Vault User Account Settings
Setting the secroot Account Expiration
Resetting the secroot Account Password
Changing CSP Vault Account Details as a Security Administrator
Re-enabling a CSP Vault-Managed User Account
Configuring Role-Based Access Control
Vault management
Creating a Vault
Rescuing a Vault
Editing a Vault
Viewing Vault Details
Renaming a Vault
Deleting a Vault
Connecting CSP Vault and CSP Compliance Manager
Initializing a Data Source Connection in CSP Compliance Manager
Connecting a CSP Vault to CSP Compliance Manager
Disconnecting a CSP Vault from CSP Compliance Manager
CSP Vault for CloudKeys
Managing Cloud Service Provider accounts
Adding a Cloud Service Provider account for AWS
Adding a Cloud Service Provider account for Azure
Adding a Cloud Service Provider account for GCP
Adding a Cloud Service Provider account for OCI
Adding a Cloud Service Provider account for SFDC
Deleting a Cloud Service Provider account
Managing key sets
Creating a key set
Importing CloudKeys
Deleting a key set
Managing CloudKeys
Creating a CloudKey
Creating a CloudKey for AWS
Creating a CloudKey for Azure
Creating a CloudKey for GCP
Creating a CloudKey for OCI
Creating a CloudKey for SFDC
Enabling a CloudKey
Disabling a CloudKey
Uploading a CloudKey
Modifying a CloudKey
Setting a syncing schedule
Removing a CloudKey
Deleting a CloudKey
Canceling a CloudKey deletion
Purging a CloudKey
Forcing a CloudKey purge
Replicating an AWS multi-region CloudKey
Changing the primary region for an AWS multi-region CloudKey
Creating a replica key for Azure
Disabling an Azure multi-vault CloudKey
Managing Vault BYOK
Configuring AWS for Vault BYOK
AWS requirements for BYOK
AWS BYOK process
AWS BYOK access policy
On-demand key rotation for AWS AES keys with BYOK
Configuring Azure for Vault BYOK
Azure requirements for BYOK
Azure BYOK process
Creating a service principal
Setting permissions for each Azure Key Vault
Creating a client secret in Azure Active Directory
Configuring GCP for CSP Vault BYOK
GCP requirements for BYOK
GCP BYOK access policy
Configuring OCI for Vault BYOK
OCI requirements for BYOK
Adding an API Key for the OCI user
Configuring SFDC for CSP Vault BYOK
SFDC requirements for BYOK
Creating a connected app in SFDC
Using cache-only keys with SFDC
Creating external named credentials
Enabling cache-only keys
Creating cache-only keys
Viewing BYOK audit logs
Managing AWS XKS
AWS XKS Requirements
AWS XKS Limitations
Configuring certificates and DNS for AWS XKS
Creating a Cloud Service Provider Account for AWS XKS
Creating a key set for AWS XKS
Creating a CloudKey for AWS XKS
Creating an external key store in AWS
Connecting AWS XKS to the CSP Vault XKS Proxy
Rotating XKS access keys
Troubleshooting AWS XKS deployment
Using CSP Vault as a GCP EKM Provider
Prerequisites for using CSP Vault as a GCP EKM provider
Manually creating EKM CloudKeys
Creating coordinated EKM CloudKeys
Using double key encryption with Vault
CSP Vault prerequisites for DKE
Creating a key set for DKE
Creating a CloudKey for DKE
Viewing CloudKey details
Creating compliance labels
Using compliance labels with MS Office
Register with Azure Entra
Managing Authentication for Vault for Cloud Keys
Configuring local authentication for Vault for Cloud Keys
Configuring Active Directory for the Vault for Cloud Keys
Configuring OIDC with Active Directory for Vault for Cloud Keys
Configuring OIDC for Vault for Cloud Keys
Managing two-factor authentication in Vault for Cloud Keys
Requirements for enabling two-factor authentication in Vault for Cloud Keys
Enforcing two-factor authentication in Vault for Cloud Keys
Disabling two-factor authentication in Vault for Cloud Keys
CSP Vault for Cryptographic APIs
CSP Vault for cryptographic APIs policies
Post quantum support in Cryptographic APIs
Cryptographic APIs sample use case
Signing in to the Vault for the first time
CSP Vault for Cryptographic APIs Crypto CLI
Wrap Command
Version Command
Verify Command
Download-Audit Command
Update-Tokenization-Settings Command
Update-Tenant-Auth-Method-To-AD Command
Update-Key-State Command
Update-Audit-Settings Command
Unwrap Command
Tokenize Command
Sign Command
Set-Key-Property Command
Schedule-Delete-Key Command
Rotate-Key Command
Renew Command
Rekey Command
Purge-Key Command
Mask Command
List-Tokenization-Policies Command
List-of-Keys Command
List-Mask-Policies Command
List-Local-User Command
List-Audit-Message-Templates Command
List-Audit-Messages Command
Import-Clear-Key Command
Get-Tokenization-Settings Command
Get-Tokenization-Policy Command
Get-Tokenization-Info Command
Get-Platform-Info Command
Get-Local-User Command
Get-Key-Versions Command
Get-Key-Value Command
Get-Keyset-Guid Command
Get-Key-Details Command
Get-HSM-Info Command
Get-Audit-Settings Command
Get-Audit-Message-Template Command
Get-AD-User Command
Get-AD-Group Command
Export-Key Command
Encrypt Command
Enable-HSM-for-Keyset Command
Detokenize-Mask Command
Detokenize Command
Delete-Tokenization-Policy Command
Delete-Local-User Command
Decrypt Command
Create-Tokenization-Policy Command
Create-Mask-Policy Command
Create-Local-User Command
Create-Key Command
Change-AD-Domain Command
Batch-Tokenize Command
Batch-Rekey Command
Batch-Mask Command
Batch-Encrypt-Decrypt Command
Batch-Encrypt Command
Batch-Detokenize Command
Batch-Decrypt Command
Get-AD-Settings Command
Update-AD-Settings Command
List-AD-Settings Command
Delete-Policy Command
Update-Access-Policy Command
Set-Policy-Version Command
List-Policy-Versions Command
Get-Policy Command
Create-Access-Policy Command
Login Command
Accessing the Crypto CLI
Managing client certificates
Creating a client certificate
Downloading a client certificate
Using the mTLS API commands
Deleting a Client Certificate
Configuring mTLS for the CSP Vault for Cryptographic APIs
Enabling or Disabling mTLS Authentication
APIs Supported with mTLS
mTLS Prerequisites
About Cache Management
Clearing the Caches
Configuring Cache Management
Configuring CSP Vault for Cryptographic APIs Policies
Deleting a Masking Policy
Editing a Masking Policy
Creating a Masking Policy
Deleting a Tokenization Policy
Editing a Tokenization Policy
Creating a Tokenization Policy
Managing Keys
Exporting keys
Importing keys
Importing a clear key using the API
Importing a key from a different Cryptographic API
Wrapping a key for import
Importing a wrapped key using the API
Importing a wrapped key in the web GUI
Creating keys
Viewing key details
Editing keys
Rotating keys
Programming key deletion
Canceling key deletion
Permanently deleting keys
Setting the password policy for users
Managing access policies and users
Creating an access policy
Editing an access policy
Deleting an access policy
Adding Cryptographic APIs users
Editing Cryptographic APIs users
Deleting Cryptographic APIs Users
Managing Authentication for Vault for Cryptographic APIs
Configuring local authentication for Vault for Cryptographic APIs
Configuring Active Directory for the Vault for Cryptographic APIs
Configuring OIDC with Active Directory for Vault for Cryptographic APIs
Configuring OIDC for Vault for Cryptographic APIs
Managing two-factor authentication in Vault for Cryptographic APIs
Requirements for enabling two-factor authentication in Vault for Cryptographic APIs
Enforcing two-factor authentication in Vault for Cryptographic APIs
Disabling two-factor authentication in Vault for Cryptographic APIs
CSP Vault for Databases
Databases supported by Vault for Databases
CSP Vault for Databases with EnterpriseDB
Manually installing and registering the policy agent for EDB PostgreSQL
Enabling TDE on EDB PostgreSQL database server
Creating a key set for EDB PostgreSQL database server
Creating a CloudKey for EDB PostgreSQL database server
Configuring the EDB PostgreSQL database connector
Configuring a cryptographic provider on the EDB PostgreSQL server
Configuring the EDB PostgreSQL server for encryption
Rotating EDB PostgreSQL keys
Backing up and restoring EDB PostgreSQL
Configuring EDB PostgreSQL scripted installation
Downloading the TDE script bundle for EDB PostgreSQL
Setting up the Entrust client using scripts for EDB
CSP Vault for databases with OpenSource PostgreSQL
Configuring Vault Authentication for CSP Vault for Databases
Configuring Active Directory for the CSP Vault for Databases
Configuring Local Authentication for CSP Vault for Databases
Configuring OIDC for the CSP Vault for Databases
Backup and Restore
Key Rotation
Functions provided by the Entrust PostgreSQL Extension
Encrypting and Decrypting Data using the PostgreSQL Server
Configuring the PostgreSQL Database Server
Configuring a Cryptographic Provider on the PostgreSQL Server
Configuring the PostgreSQL Database Connector
Creating a CloudKey for PostgreSQL Database Server
Creating a Key Set for PostgreSQL Database Server
Enable TDE on PostgreSQL Database Server
Manually Installing and Registering the Policy Agent for PostgreSQL
Installing PostgreSQL
CSP Vault for Databases with MariaDB TDE
Common MariaDB Queries for Manual or Scripted Installation
Manual Installation and Configuration for Maria DB
Scripted Installation and Configuration1
Common MariaDBQueries for Manual or Scripted Installation
Downloading the TDE Script Bundle for MariaDB
Encrypting Tables on MariaDB Server
Setting up the Entrust Client on MariaDB Using Scripts
Setting up Data Guard with Scripts
Configuring Auto-login for the Keystore on the Standby Node
Migrating from Software Wallet with Data Guard
Primary Key Rotation with Data Guard
Switch Standby Node to Primary with Data Guard
Scripted Installation and Configuration for Oracle TDE
Scripted Backup and Restore with Oracle TDE
Backing Up Oracle TDE on an Encrypted Database
Restoring Oracle TDE Using Scripts
Viewing TDE Reports for Oracle Database
Remove Entrust Software from Oracle with Scripts
Rotating the TDE Key using Scripts
Reverse Migrate to Software Wallet using Scripts
Configuring Auto-login for the Keystore using Scripts
Migrating from Software Wallet using Scripts
Encrypting Multiple Oracle Databases with one Command
Scripted Database Encryption with TDE Keys
Enabling TDE on a Non-Encrypted Oracle Database using Scripts
Setting up the Entrust Client Using Scripts for Oracle
Downloading the TDE Script Bundle for Oracle
Prerequisites for Scripted Oracle TDE
CSP Vault with Oracle TDE
Migrating from Software Keystore to CSP Vault
Migrating from Software Wallet to CSP Vault
Configuring Auto-Login with Oracle RAC for the CSP Vault Keystore on ASM Wallet
Configuring Auto-Login for the CSP Vault Keystore
Oracle TDE Key Rotation
Oracle TDE Keys in Cryptographic Security Platform Vault
Creating a Key Set for Oracle Database Server TDE
Oracle RAC Cluster Setup
Configuring CSP Vault for Oracle TDE on the Second Node
Configuring the Oracle Server Database on the Second Node
Configuring the Oracle Server Cryptographic Library on the Second Node
Installing the CSP Vault Linux Policy Agent for Oracle TDE on the Second Node
Oracle Single Node Setup
Configuring CSP Vault for Oracle TDE
Configuring the Oracle Server Cryptographic Library
Configuring the Oracle Server Database
Configuring the Oracle Server Database Encryption with TDE Key
Installing the Cryptographic Security Platform Vault Linux Policy Agent for Oracle TDE
Manual Installation and Configuration for Oracle TDE
CSP Vault as EKM Provider for Microsoft SQL Server
Cell-Level Encryption (CLE)
Database Backup and Restore
Backing up the TDE Encrypted Database
Restoring the TDE Encrypted Database
Restoring the TDE Encrypted Database on an Alternate (Failover) VM
Encryption and Keys
Introduction of Microsoft SQL Server
Microsoft SQL Server Manual Installation and Configuration
Configuring a CSP Vault Database Connector
Configuring Microsoft SQL Server for EKM
Creating a Cloud VM Set for Microsoft SQL Server TDE
Creating a Key Set for Microsoft SQL Server TDE
Enable TDE on SQL Server
Installation Requirements for Microsoft SQL Server TDE
Installing and Registering the Policy Agent for SQL Server
Removing Microsoft SQL Server TDE from the CSP Vault for Databases
Rotating Microsoft SQL Server Keys
Scripted Installation and Configuration
Checking your Microsoft SQL Server Connections
Downloading the TDE Script Bundle for Microsoft SQL Server
Encrypting the Database on the Active SQL Server Node
Rotating the Master Key on the Active SQL Server Node
Setting up the Entrust Client Using Scripts
Setting Up a Microsoft SQL Server Cluster for TDE
Transparent Data Encryption (TDE)
Configuring Microsoft SQL Server Database Encryption with TDE Key
Viewing Tables and Checking Keys
T-SQL Shortcuts and Tips
Viewing TDE Reports for Microsoft SQL Server
Creating a Cloud VM Set for the CSP Vault for Databases
Changing a Cluster Node Mapping for CSP Vault for Databases
Creating a Cluster Node Mapping for CSP Vault for Databases
Disabling a CloudKey or All CloudKey Versions
Creating a CloudKey for TDE
Creating a Key Set for TDE
Managing Authentication for Vault for Databases
Configuring local authentication for Vault for Databases
Configuring Active Directory for the Vault for Databases
Configuring OIDC with Active Directory for Vault for Databases
Configuring OIDC for Vault for Databases
Managing two-factor authentication in Vault for Databases
Requirements for enabling two-factor authentication in Vault for Databases
Enforcing two-factor authentication in Vault for Databases
Disabling two-factor authentication in Vault for Databases
CSP Vault for KMIP
CSP Vault for KMIP KMIPCLI
Accessing the KMIPCLI
Change-AD Domain Command
Completion Command
Configure-HSM-KEK Command
Create-Client-Cert Command
Create-Local User Command
Create-Policy Command
Delete-Client-Cert Command
Delete-Local User Command
Delete-Policy-Command
Disable-KMIP-KEK Command
Download Audit Command
Download-Client-Cert Command
Get-AD Group Command
Get-AD Settings Command
Get-AD User Command
Get-Audit-Message Template Command
Get-Audit Settings Command
Get-Client-Cert Command
Get-HSM Info Command
Get-KEK-Setting Command
Get-KMIP-Object Command
Get-KMIP-Object-Count Command
Get-Local User Command
Get-Personal-Access-Token Command
Get-Platform Info Command
Get-Policy-Command
Get-Vault-Info Command
Get-Vault-Settings Command
KMIPCLI Examples
KMIPCLI Overview
List-AD Settings Command
List-Audit Messages Command
List-Audit-Message Templates Command
List-Client-Certs Command
List-KMIP-Objects Command
List-Local-Users Command
List-Personal-Access-Tokens Command
List-Policies Command
List-Policy Versions Command
Locate-Root-Key Command
Login-Command
Rekey-KMIP-KEK Command
Renew-Command
Set-Policy Version Command
Update-AD Settings Command
Update-Audit Settings Command
Update-KMIP-Object Command
Update-Local-User Command
Update-Personal-Access-Token Command
Update-Policy Command
Update-Vault-Auth-Method-to-AD Command
Update-Vault-Settings Command
Version-Command
Resetting KMIP Vaults
Rekeying KMIP Objects in the CSP Vault for KMIP webGUI
KEK with a KMIP Vault
Viewing CSP Vault for KMIP Audit Logs
Managing KMIP Objects in the CSP Vault for KMIP webGUI
Managing KMIP Client Certificates
Creating a KMIP Client Certificate
CSP Vault for KMIP Access Policies
KMIP Cluster Considerations
Configuring a new KMIP Server
Post Quantum Support in the CSP Vault for KMIP
KMIP Vault Overview
Managing Authentication for Vault for KMIP
Configuring local authentication for Vault for KMIP
Configuring Active Directory for the Vault for KMIP
Configuring OIDC with Active Directory for Vault for KMIP
Configuring OIDC for Vault for KMIP
Managing two-factor authentication in Vault for KMIP
Requirements for enabling two-factor authentication in Vault for KMIP
Enforcing two-factor authentication in Vault for KMIP
Disabling two-factor authentication in Vault for KMIP
CSP Vault for PKCS#11
Setting up the PKCS#11 Vault
Requirements to set up the PKCS#11 vault
Creating a PKCS#11 Vault
Logging in to the PKCS#11 Vault
Configuring a port
Adding a Softcard
Configuring service log level
Generating a private key and a CSR
Creating a PKCS#11 client certificate
Configuring the PKCS#11 Vault client
Using the client
Capabilities
Logging
Managing Authentication for Vault for PKCS#11
Configuring local authentication for Vault for PKCS#11
Configuring Active Directory for the Vault for PKCS#11
Configuring OIDC with Active Directory for Vault for PKCS#11
Configuring OIDC for Vault for PKCS#11
Managing two-factor authentication in Vault for PKCS#11
Requirements for enabling two-factor authentication in Vault for PKCS#11
Enforcing two-factor authentication in Vault for PKCS#11
Disabling two-factor authentication in Vault for PKCS#11
CSP Vault for Secrets
CSP Vault for Secrets Overview
About Cryptographic Security Platform Vault for Secrets Boxes
About Secondary Approval
About Secrets
Creating CSP Vault for Secrets Local Users
CSP Vault for Secrets Access Policies
Download the CSP Vault CA Certificate
Hardware Security Modules with CSP Vault for Secrets
Setting the Password-Policy for Users
Using HSM with CSP Vault for Secrets
Viewing CSP Vault for Secrets
CSP Vault for Secrets CLI
Accessing the PASM CLI
PASM CLI Cancel-CSV-Import Command
PASM CLI Checkin-Secret Command
PASM CLI Checkout-Secret Command
PASM CLI Create-Box Command
PASM CLI Create-File-Secret Command
PASM CLI Create-KV-Secret Command
PASM CLI Create-Local-User Command
PASM CLI Create-Policy Command
PASM CLI Create-Pwd-Secret Command
PASM CLI Create-Secret Command
PASM CLI Create-SSH-Key-Secret Command
PASM CLI Delete-Box Command
PASM CLI Delete-Lease Command
PASM CLI Delete-Policy Command
PASM CLI Delete-Secret Command
PASM CLI Download-Audit Command
PASM CLI Download-Sample-CSV Command
PASM CLI Download-SSH-Proxy-Audit Command
PASM CLI Generate-Password Command
PASM CLI Get-AD-Setting Command
PASM CLI Get-Audit-Message-Template Command
PASM CLI Get-Audit-Setting Command
PASM CLI Get-Box Command
PASM CLI Get-CSV-Import-Status Command
PASM CLI Get-Lease Command
PASM CLI Get-Policy Command
PASM CLI Get-Secret Command
PASM CLI Get-Secret-Value Command
PASM CLI Import-CSV Command
PASM CLI List-AD-Settings Command
PASM CLI List-Audit-Messages Command
PASM CLI List-Audit-Message-Templates Command
PASM CLI List-Boxes Command
PASM CLI List-Box-IDs Command
PASM CLI List-Leases-by-Secret Command
PASM CLI List-Leases Command
PASM CLI List-My-Checkouts Command
PASM CLI List-Policies Command
PASM CLI List-Policy-Versions Command
PASM CLI List-Secret-IDs Command
PASM CLI List-Secrets Command
PASM CLI List-Secret-Versions Command
PASM CLI Login Command
PASM CLI Put-File-Secret Command
PASM CLI Put-Secret-Value Command
PASM CLI Put-SSH-Key-Secret-Value Command
PASM CLI Rotate-Secret Command
PASM CLI Tag-Box Command
PASM CLI Tag-Secret Command
PASM CLI Untag-Box Command
PASM CLI Untag-Secret Command
PASM CLI Update AD Setting Command
PASM CLI Update-Audit-Setting Command
PASM CLI Update-Box Command
PASM CLI Update-Policy Command
PASM CLI Update-Secret Command
PASM CLI Version Command
Viewing CSP Vault for Secrets Audit Logs
Configuring mTLS for the CSP Vault for Secrets
Using a mTLS API Commands
Creating Client Certificate
Deleting the Client Certificate
Downloading the Client Certificate
Enabling or Disabling-mTLS Authentication
mTLS-Prerequisites
Managing Secrets
Viewing Static Secret
Removing Tags from a Secret
Importing a Secret
Checking in a Secret
Deleting a Secret
Editing a Secret
Creating a Secret
Creating an Azure User Credentials Secret
Creating an AWS User Credentials Secret
Creating a Microsoft SQL Server Secret
Creating a Postgres or EnterpriseDB Postgres Secret
Creating a Terraform Secret
Creating a P12 Secret
Creating an SSH Secret
Logging on to remote server using SSH Secret
About SSH Secrets
Creating a Text Secret
Creating a Password Secret
Creating a Key-Value Pair Secret
Creating a File Secret
Creating an ESXi Host Secret
Checking-Out a Managed Secret
Assigning Tags to a Secret
Accessing Secrets
Checking Out a Managed Secret
Viewing a Static Secret
Managing Boxes
Removing Tags from a Box
Adding Tags to a Box
Remove Rotation
Rotate All Secrets in a Box
Editing an Existing Box
Deleting a Box
Creating a Box
Managing Authentication for Vault for Secrets
Configuring local authentication for Vault for Secrets
Configuring Active Directory for the Vault for Secrets
Configuring OIDC with Active Directory for Vault for Secrets
Configuring OIDC for Vault for Secrets
Managing two-factor authentication in Vault for Secrets
Requirements for enabling two-factor authentication in Vault for Secrets
Enforcing two-factor authentication in Vault for Secrets
Disabling two-factor authentication in Vault for Secrets
CSP Vault for VM Encryption
VM Encryption Vault Overview
Microsoft Failover Clusters
Decommissioning or Decrypting an Encrypted Drive Shared by Multiple Nodes
Testing Failover and Failback
Enabling Failover and Failback
Dependencies for Failover and Failback
Encrypting a Drive Shared by Multiple Nodes
Windows Boot Drive Encryption
Encrypting a Windows Boot Drive
Bootloader Diagnostic Files
Bootloader Time Sync Issues
Troubleshooting Windows Boot Drive Issues
Setting the Preferred Network Adapter
Changing the Bootloader Network Settings
Automated Bootloader Installation
Installing the Bootloader After the Policy Agent Is Installed
Access Management for Windows Boot Drives
The Boot Process
Requirements for Windows Boot Drive Encryption
Windows Boot Drive Encryption Overview
Linux Root, Swap, and System Device Encryption
Checking the Root Drive Encryption Status
Encrypting Linux System Devices
Verifying the Current VM Configuration
Prerequisites and Restrictions
Creating a Boot Partition on RHEL 8, 9, and 10
Creating a Boot Partition on the AWS Root Volume
Creating a Boot Partition on Ubuntu
Data Encryption
Migrating Files into AWS S3 Buckets
Troubleshooting hcs3 Failures
hcs3 Properties
Enabling hcs3 Access to Non-Root Users
Viewing a Bucket's Status and Contents
Adding and Removing Files from Buckets
Creating and Managing Buckets
Using Environment Variables for AWS Credentials
The hcs3 Interface
Using Asymmetric KeyIDs
Deleting an Asymmetric KeyID
Managing Asymmetric KeyID Access
Managing Asymmetric KeyIDs
Creating an Asymmetric KeyID
File-Level Encryption Using KeyIDs
Deleting KeyIDs
Managing KeyID Access
Changing KeyID Properties
Envelope Encryption Using KeyIDs
Using KeyIDs for Encryption and Decryption
Creating KeyIDs in the webGUI
Creating KeyIDs with the CLI
Configuring Client-Side Key Caching
Changing the Encryption/Decryption Speed on Windows
Changing Encryption/Decryption Speed on a Disk
Changing the Encryption/Decryption Speed on a VM
Viewing Encryption/Decryption Settings
Example: Encrypting a Windows VM with New Disks
Example: Encrypting a Linux LVM Volume
Example: Adding an Encrypting a Linux Disk with XFS
Combining VMware vSphere VDI with the CSP Vault
Removing Expired Clones
Decrypting a Linux System Device
Decrypting a Disk Using the CLI
Decrypting a Disk Using the Windows Policy Agent GUI
Decrypting a Disk Using the webGUI
Encryption Key Maintenance
Setting the Key Expiration Date for a Disk
Pausing a Rekey Operation on Windows
Configuring Auto Rekey for a VM
Configuring Auto Rekey for a Cloud VM Set
Rekeying a Linux System Device
Rekeying a Disk using the CLI
Rekeying a Disk using the Policy Agent GUI
Rekeying a Disk Using the webGUI
Windows Encryption Management with the Entrust Policy Agent GUI
Encrypting a Windows Disk Using the Entrust Policy Agent GUI
Troubleshooting Windows Online Encryption Issues
Reversing an Encryption
Encrypting a Disk Using the CLI
Encrypting a Disk Using the CSP Vault for VM Encryption webGUI
Automatic Data Encryption
Configuring Automatic Data Encryption for a VM
Configuring Automatic Data Encryption for a Cloud VM Set
Prerequisites and Considerations for Automatic Data Encryption
Using Data Encryption in Microsoft Azure
Checking the Root Drive Encryption Status in Azure
Encrypting Linux System Devices in Azure
Verifying the Current VM Configuration in Azure
Preparing a Linux System Device for Encryption in Azure
Partitioning a Linux OS Disk in Azure
Prerequisites and Restrictions for Azure
Data Encryption in Azure
Using Data Encryption in AWS
Checking the Root Drive Encryption Status in AWS
Encrypting Linux System Devices in AWS
Verifying the Current VM Configuration in AWS
Creating a Boot Partition on a New AWS Volume
Creating a Boot Partition on the Existing AWS Root Volume
Prerequisites and Restrictions for AWS
Data Encryption in AWS
Windows Encryption Prerequisites
Detecting and Removing a Windows Snapshot Partition
Linux Encryption Overview
Changing the Mount Order on Linux
Automatically Mounting Linux Filesystems
Troubleshooting the HTCrypt Driver
Uninstalling the HTCrypt Driver
Updating the HTCrypt Kernel Dependencies
Configuring UEFI Secure Boot
Configuring UEFI Secure Boot in Ubuntu
Configuring UEFI Secure Boot in RHEL or Oracle Linux
Viewing HTCrypt Driver Status
Enabling Linux Online Encryption with the CSP Vault for VM Encryption webGUI
Enabling Linux Online Encryption with the CLI
Linux Online Encryption Prerequisites and Considerations
Linux Encryption Prerequisites
Data Encryption Overview
VM and Disk Management
Decommissioning and Destroying a VM
Removing a Disk from the CSP Vault for VM Encryption
Removing a VM from the CSP Vault for VM Encryption
Reactivating a Revoked Disk
Revoking Access to a Disk
Revoking VM Permissions
Disk Size Management in Windows
Disk Size Management in Linux
Decreasing the Size of an LVM Volume
Decreasing the Size of a Linux Data Partition
Expanding an LVM Swap Volume
Expanding an LVM Data or Root Volume
Expanding a Linux Data Partition
Expanding a Swap Partition
Expanding a Root Partition
Changing the Drive Letter for a Windows Disk
Moving a VM to a Cloud VM Set
Moving Disks Between VMs
Viewing the Details for a Disk
Using the Dashboard
Backups, Clones, and Snapshots
Registering a Linux or Windows Root-Drive-Encrypted Cloned VM with Simplified Authentication
Registering a Cloned VM with Simplified Authentication
Registering a Cloned VM with Standard Authentication
Restoring a VM from a Snapshot
Re-Authenticating a Windows VM with the Entrust Policy Agent GUI
Re-Authenticating a VM with an Encrypted Root Device or Boot Disk
Re-Authenticating a Standard VM
Access Control Policies
Deleting an Access Control Policy
Removing Access Controls from a Disk
Viewing the Access Control Status for a Disk
Associating an Access Control Policy with a Disk
Enabling Access Controls on a Linux VM
Viewing the Change History for an Access Control Policy
Changing a Windows Access Control Policy
Changing a Linux Access Control Policy
Creating a Windows Access Control Policy
Creating a Linux Access Control Policy
Changing the AD Server Configuration
Managing Active Directory Server Associations
Associating an AD Server with a Cloud Administration Group
Windows Access Control Rule Recommendations and Considerations
Windows Access Control Rule Processing
Access Control Rule Types
Implementation Differences Between Linux and Windows
Access Control Requirements and Considerations
VM Certificates
Revoking a Client Certificate
Viewing Client Certificates
Renewing a VM Certificate
Changing the Properties for a Specific VM
Viewing the VM Status with the CLI
Exporting VM Details
Viewing the Details for a VM
High Availability Between a VM and the CSP Vault Cluster
Updating CSP Vault Node IP Addresses on an Individual VM
Managing the Cluster Node Mapping on a VM
Changing a Cluster Node Mapping
Creating a Cluster Node Mapping
Cloud VM Sets
Changing Cloud VM Set Properties
Revoking KEK Access
Viewing the SEK Key Version for a Disk
Changing the SEK Key Expiration Options
Changing SEK Properties
Generating a New SEK Key
Changing KEK Properties
Adding KEK to an Existing Cloud VM Set
Creating a Cloud VM Set for the CSP Vault for VM Encryption
Setting Default Cloud VM Set Properties
Data Deduplication with Cloud VM Sets
KEKs with Cloud VM Sets
Effects of Encryption on Thin-Provisioned Disks
Configuring Vault Authentication for CSP Vault for VM Encryption
Configuring Active Directory for the CSP Vault for VM Encryption
Configuring Local Authentication for CSP Vault for VM Encryption
Managing Authentication for Vault for VM Encryption
Configuring local authentication for Vault for VM Encryption
Configuring Active Directory for the Vault for VM Encryption
Configuring OIDC with Active Directory for Vault for VM Encryption
Configuring OIDC for Vault for VM Encryption
Managing two-factor authentication in Vault for VM Encryption
Requirements for enabling two-factor authentication in Vault for VM Encryption
Enforcing two-factor authentication in Vault for VM Encryption
Disabling two-factor authentication in Vault for VM Encryption
External Authentication Provider Examples
Example: Configuring Azure OIDC to use with CSP Vault
Example: Configuring Entrust Identity as a Service
Personal Access Tokens
Creating a Personal Access Token
Deleting a Personal Access Token
Cloud Admin Groups and CSP Vault User Accounts
Cloud Admin Groups
Deleting a Cloud Admin Group
Changing a Cloud Admin Group
Creating a Custom Cloud Admin Group
Considerations when using AD Security Groups
Cloud Admin Groups Overview
Upgrading CSP Vault
CSP Vault Upgrade Paths
CSP Vault Upgrade Requirements
Upgrading CSP Vault to 10.6.1
Installing Policy Agent
Preparing to Install the Policy Agent
Linux Policy Agent Installation
Linux Policy Agent Installation Overview
Linux Installation Prerequisites
Installing the Policy Agent on Linux
Authenticating a New VM
Windows Policy Agent Installation
Windows Installation Prerequisites
Windows Boot Drive Installation Prerequisites
Installing Interactively on Windows
Installing Silently on Windows
Registering the Policy Agent Using the Entrust Policy Agent GUI
Registering the Policy Agent from the Windows command line
Uninstalling Silently on Windows
Upgrading Policy Agent
Policy Agent Upgrade Requirements
Upgrading Policy Agent with the webGUI
Upgrading the Policy Agent on Linux
Upgrading the Policy Agent on Windows
CSP Vault Appliance Management
CSP Vault System Configuration
Enabling an HTTP Proxy Server in CSP Vault
Network Interface Configuration Options
Multi-NIC Node Configuration
Configuring Multiple NICs on an Existing CSP Vault
Removing a NIC from the Configuration
Configuring DNS Settings
Configuring NTP Settings
Configuring Static Routes
Configuring TLS
Uploading an OIDC CA Certificate
Setting Email Server Preferences
Setting CSP Vault Console Settings
Syslog Server Settings
Configuring Syslog Server Settings
Resetting Syslog Server Settings
CSP Vault Certificates
About CSP Vault Certificates
Viewing the Expiration Date for the Current CSP Vault SSL Certificate
Creating a Certificate Signing Request
Using Self-Signed Certificates for All Nodes in a Cluster
Generating and Installing a Custom Self-Signed Certificate
Installing External Certificates for Internal and External Webservers
CSP Vault Certificate Expiration Notification
Installing a New Self-Signed Certificate for a Node
Downloading a CSP Vault CA Certificate
Troubleshooting Certificate Issues
Manually Updating the CA Certificate on a Linux Root Drive Encrypted VM
Manually Updating the CA Certificate on a Data Encrypted VM
Manually Updating the CA Certificate on a Windows Boot Drive Encrypted VM
Admin Keys
Downloading Your Admin Key Part
Generating the Admin Key
Verifying the Admin Key
KMIP Server Configuration
KEKs with KMIP
Configuring a New KMIP Server (orig)
Creating a Certificate Signing Request for KMIP Server
Installing a Custom Certificate
Hardware Security Modules with CSP Vault
Adding a CSP Vault Node to a Cluster using an nShield HSM client
Configuring CSP Vault as an HSM Client using an nShield HSM
Adding HSM Root-of-Trust to nShield Server
Running nShield HSM Info Commands in the webGUI
Configuring an nShield HSM for High Availability
Replacing an nShield HSM on a CSP Vault Cluster
Configuring Allowed Smart Cards for an nShield HSM
KeySafe5 Agent Requirements
Enabling the KeySafe5 Agent
Configuring CSP Vault as a Luna Cloud HSM Client
Configuring CSP Vault as a Luna HSM Client with a Single Cluster Certificate
Configuring CSP Vault as a Luna HSM Client with Individual Node Certificates
Configuring a Luna HSM HA Group
Adding a CSP Vault Node to an Existing Luna HSM Configuration
Adding a New Luna HSM to an Existing Luna HSM Configuration
Adding a Luna Cloud HSM to an Existing Luna HSM Configuration
Changing the Luna Client Certificate Mode
Locating the HSM Server Admin Key
Resetting the HSM Server Configuration
SNMP Traps in Cryptographic Security Platform Vault
Configuring Group-Level SNMP Traps
Configuring SNMP Agent Users for Polling
Configuring System-Level SNMP Traps
Downloading the SNMP MIB File
SNMP MIB File
Setting CSP Vault Management webGUI Alert Settings
Using the Entrust CSP Vault System Console
CSP Vault Cluster Maintenance
CSP Vault Nodes and Clusters
Viewing the Cluster Status
Setting Cluster Options
Switching a Master Node
Choosing the Node Failover Order
Startup Authentication
Enabling Startup Authentication
Disabling Startup Authentication
CSP Vault Backup and Restore
Backing Up CSP Vault Through the webGUI
Backup and Restore Using the API
Backup Image Status
Create Object Store Backup Image
Creating a Backup User
Download Object Store Backup Image
Restore Backup Image
Restoring CSP Vault Through the webGUI
Joining or Re-joining a Cryptographic Security Platform Vault Cluster
Joining a CSP Vault Cluster
Re-Joining a CSP Vault Cluster
Upload Backup Image
Removing a CSP Vault Node from a Cluster
Changing the IP Address for a Node
Rebooting a CSP Vault Node
Decommissioning a CSP Vault Node
Enabling or Disabling the Support Login
Accessing CSP Vault Backup Files
CSP Vault System Maintenance and Troubleshooting
CSP Vault Activity Tracking
Managing Alerts
Viewing the Audit Log
Configuring Audit Log Settings
Exporting the Audit Log
Moving a CSP Vault Node to a New Server in a Multi-Node Environment
Moving a CSP Vault Node to a New Server in a Single Node Environment
Increasing CSP Vault Storage in a VM
VM Handlers for Attach/Detach in Linux
VM Handlers for Attach/Detach in Windows
Upgrading to a New Hardware Signature Format
Troubleshooting Network Issues
Cleaning Up Stale Tasks
Support Access and Log Files
Using the Restricted Shell
Creating a Support Bundle with the webGUI
Creating a Support Bundle from the CSP Vault System Console
Disabling CSP Vault Support Logins
Policy Agent Support Logs
Backing Up the Policy Agent
Uninstalling the Policy Agent on Linux
Uninstalling the Policy Agent on Windows
KMIP Errors and Troubleshooting
Revert to Previous CSP Vault Version
Delete CSP Vault Snapshots
Troubleshooting CSP Platform Vault from the Bootloader
Recovering Access to CSP Vault
CSP Vault Management webGUI Page Reference
Alerts Page
Audit Log Page
Cluster Page
HSM Server Settings Page
Proxy Settings
Users Page
Settings Page
SNMP Settings Page
License Page
Syslog Server Settings Page
System Decommission Page
System Upgrade Page
CSP Vault Audit Messages 10.6.1
CSP Vault Audit Messages
CSP Vault for Cryptographic APIs Audit Messages
CSP Vault for KMIP Audit Messages
CSP Vault for PKCS#11 Audit Messages
CSP Vault for Secrets Audit Messages
Differences in CSP Vault Audit Messages
hicli scripting guide
Command reference
alert detail <alertnum>
alert list
alert rm <alertid>
create_bucket
delete_bucket
global set
hicli byok log <group>
hicli cert detail
hicli cert new
hicli cert rm
hicli cloudkey delete_from_cloud
hicli cloudkey detail
hicli cloudkey disable
hicli cloudkey ekm_acls
hicli cloudkey enable
hicli cloudkey getpublickey
hicli cloudkey has_ekm_acls disable
hicli cloudkey has_ekm_acls enable
hicli cloudkey import
hicli cloudkey kaj_policy
hicli cloudkey keyops
hicli cloudkey list
hicli cloudkey new
hicli cloudkey policy_get
hicli cloudkey policy_set
hicli cloudkey purge
hicli cloudkey rm
hicli cloudkey roles_get
hicli cloudkey roles_set
hicli cloudkey rotate
hicli cloudkey set
hicli cloudkey set_primary
hicli cloudkey tag clear
hicli cloudkey tag list
hicli cloudkey tag set
hicli cloudkey upload_to_cloud
hicli cloudkey users
hicli cloudkey versions
hicli csp cert_auth
hicli csp detail
hicli csp ekm_acls
hicli csp ekmconnections
hicli csp get_cert_details
hicli csp kaj_policy
hicli csp kaj_policy_state
hicli csp key_algorithms
hicli csp keyrings
hicli csp keyvaults
hicli csp list
hicli csp managedhsms
hicli csp new
hicli csp regions
hicli csp rm
hicli csp roles
hicli csp rotate
hicli csp set
hicli csp users
hicli cvm add_disk
hicli cvm decrypt_task
hicli cvm detail
hicli cvm detail_disk
hicli cvm encrypt_task
hicli cvm list
hicli cvm list_tasks
hicli cvm new
hicli cvm reauth
hicli cvm rekey_task
hicli cvm renew clone
hicli cvm revoke
hicli cvm revoke_disk
hicli cvm rm
hicli cvm rm_disk
hicli cvm s3 add_file
hicli cvm s3 get_file
hicli cvm s3 rm_file
hicli cvm select
hicli cvmset
hicli cvm set
hicli cvm set_disk expiration
hicli cvm set_mapping
hicli cvmset add_kek
hicli cvmset detail
hicli cvmset kek_edit
hicli cvmset kek_state_change
hicli cvmset list
hicli cvmset list_tasks
hicli cvmset new
hicli cvm set rekey
hicli cvmset select
hicli cvmset set
hicli cvmset set grace
hicli cvmset set heartbeat
hicli cvmset set name
hicli cvmset set rekey
hicli cvmset set rekeybucket
hicli cvm status
hicli cvm unrevoke_disk
hicli domain detail
hicli domain list
hicli domain select
hicli domain set
hicli domain set allow_reconnect
hicli domain set description
hicli domain set hide_passphrase
hicli generate_csr
hicli group add_user
hicli group detail
hicli group list
hicli group new
hicli group rm
hicli group rm_user
hicli group set
hicli group set description
hicli group set name
hicli kc
hicli kc select <kchost>
hicli keyid new
hicli keyid revoke
hicli keyid rm
hicli keyid set expiration
hicli keyid set onexpiry
hicli keyid unrevoke
hicli keyset add_tde_connector
hicli keyset container_purge
hicli keyset create_tde_connector_token
hicli keyset detail
hicli keyset keyrings
hicli keyset list
hicli keyset list_tde_connectors
hicli keyset new
hicli keyset rm
hicli keyset select
hicli keyset set
hicli keyset set_sync_schedule
hicli keyset tde_connector delete
hicli keyset tde_connector disable
hicli keyset tde_connector enable
hicli keyset verify_hsm
hicli keyset verify_tde_connector_token
hicli mapping detail
hicli mapping list
hicli mapping new
hicli mapping rm
hicli mapping select
hicli mapping set description
hicli mapping set group
hicli mapping set newname
hicli mapping set servers
hicli server auth
hicli server auth
hicli server default_csr_values
hicli server detail
hicli server install_cert
hicli server install_cert_status
hicli server show_cert
hicli server use_default_certs
hicli server webserver_restart
hicli user defaults
hicli user detail <username>
hicli user list
hicli user login <name>
hicli user new <username>
hicli user rm <username>
hicli user set <username>
kmipsrv_obj action uuid
kmipsrv_obj fetch
kmipsrv_user
kmipsrv set
list_bucket
s3 add_file
s3 get_file
s3 rm_file
set aws_access_key_id
set aws_secret_access_key
Customer license
CSP Vault with VSAN and VMware vSphere VM Encryption
CSP Vault with VSAN and VMware vSphere VM Encryption Overview
Configuring a KMIP Server for vSphere KMS
Adding a KMS Cluster in vSphere
Establishing a Trusted Connection with a vSphere-Generated CSR
Establishing a Trusted Connection with a CSP Vault-Generated CSR
Troubleshooting