4 ms·
Vault is phenomenal. Do you know by chance whether Vault has a pkcs11 Plug-in? So one can offload certain crypto operations into an HSM? (apart from the masterk
by weitzj 7y ago
Vault is phenomenal. Do you know by chance whether Vault has a pkcs11 Plug-in? So one can offload certain crypto operations into an HSM? (apart from the masterkey)
i.e. I would like to use the PKI from vault but the key of the CA has to live in an HSM.
- Operyl 7y agoWould a trade off be having an intermediary for your CA that vault controls the key for? That seems to be the common configuration I’ve seen at least.
- weitzj 7y agoThis is the configuration I would prefer as well. But for my question I already had an intermediate CA in mind and where to store its key. The rootca is offline
- Daegalus 7y agoWe use Vault Enterprise at my company, and I do a lot of the deployment/adminsitration of vault. The enterprise version supports PKCS11 and external HSM: https://www.vaultproject.io/docs/configuration/seal/pkcs11.html https://www.vaultproject.io/docs/configuration/seal/pkcs11.h... and https://www.vaultproject.io/docs/configuration/entropy-augmentation/index.html https://www.vaultproject.io/docs/configuration/entropy-augme... for reference. https://learn.hashicorp.com/vault/operations/ops-seal-wrap https://learn.hashicorp.com/vault/operations/ops-seal-wrap is a guide linked at the bottom
- weitzj 7y agoThanks. So to fully understand this - if I use seal wrapping with an HSM all secrets in Vault will be wrapped by the HSM and not only the masterkey/autounseal? And even though the rest is then in software (Vault) I still have the same FIPS level as the HSM?
- viralpoetry 7y agothere is an issue to track this one already https://github.com/hashicorp/vault/issues/6991 https://github.com/hashicorp/vault/issues/6991