This page lets you configure the connection settings between Cryptographic Security Platform Vault and an Entrust or third-party Hardware Security Module (HSM).
An HSM is a physical server or PCI card that stores, protects, and manages cryptographic material. An HSM is often used to do cryptographic processing as well, including the generation of secure cryptographic keys. It is used in a client-server environment, which means that the server and the client each need to be prepared in advance. As with KMIP, the advantage of an HSM is that it protects and stores critical data such as your Admin Key and any Key Encryption Keys (KEKs) you have created for your Cloud VM Sets.
For details, see:
- Hardware Security Modules with CSP Vault
- Configuring Cryptographic Security Platform Vault as an HSM Client using an nShield HSM
- Adding a Cryptographic Security Platform Vault Node to a Cluster using an nShield HSM client
- Adding HSM Root-of-Trust to nShield Server
- Configuring Allowed Smart Cards for an nShield HSM
- Configuring an nShield HSM for High Availability
- Replacing an nShield HSM on a Cryptographic Security Platform Vault Cluster
- Configuring Cryptographic Security Platform Vault as a Luna HSM Client with a Single Cluster Certificate
- Configuring CSP Vault as a Luna HSM Client with Individual Node Certificates
- Adding a Cryptographic Security Platform Vault Node to an Existing Luna HSM Configuration
- Resetting the HSM Server Configuration
- Admin Keys
- KEKs with Cloud VM Sets