Integrating an External Hardware Security Module (HSM)

As an alternative to the native software cryptography, you can integrate a network Entrust® nShield™ Connect HSM as an external HSM with the ActivID Appliance.

The Hardware Security Module (HSM) is responsible for encryption, decryption, key management, and digital signature creation and validation. This includes the following cryptographic operations:

  • Encrypting and decrypting database-sensitive information (that is, credentials, passwords, security questions and answers).

  • Encrypting the hash of database row signatures.

Note: For the supported external HSMs, see Cryptography.

To integrate the Entrust nShield Connect HSM with the ActivID Appliance, perform the following steps:

  1. Prepare the HSM and RFS for the appliance:

    • Install the Entrust Security World Software for nShield (recommended version 12.60.11), the software that facilitates the integration of the Entrust nShield Connect HSM with the appliance.

    • Create the HSM Keys (protected by the module or OCS card) to be used by the ActivID Appliance.

    • Create the Operator Card Sets.

    • Create the ActivID IDP keys and certificates.

  2. Configure the appliance for the external HSM.

  3. Migrate to the external HSM.

Topics in this section: