CSP Vault for PKCS#11 provides a PKCS#11 interface for applications that use keys and cryptographic operations managed by a CSP Vault and backed by an nShield HSM. The client communicates securely with the Vault server using mutual TLS (mTLS).

  • PKCS#11 is a public standard that defines an API for interacting with hardware security modules (HSMs). CSP Vault for PKCS#11 includes a lightweight client that communicates with the nShield HSMs used by the CSP Vault cluster. The PKCS#11 client implements https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.2/pkcs11-spec-v3.2.html
  • CSP Vault includes a PKCS#11 server that listens for secure client connections. Client libraries are available for Linux and Windows on x86-64 platforms. The client establishes a mutually authenticated TLS (mTLS) connection to the PKCS#11 server and must use a client certificate issued by CSP Vault.
  • The client serializes PKCS#11 function calls and their parameters and sends them to the PKCS#11 server running in the CSP Vault cluster. The server passes the requests to the nShield libcknfast.so library, which communicates with the HSMs and returns the results to the client. See https://nshielddocs.entrust.com/security-world-docs/api-pkcs11/intro.html for details.
  • Release 10.6.1 supports module protection and softcard protection. Data used by CSP Vault for PKCS#11 is isolated from data used by other CSP Vault service.

See below for the configuration steps.