Skip to main content

Prerequisites

Please ensure the following requirements are met:

  • FortiWeb with FortiOS v7.6.3 and newer (has the Securosys PKCS#11 Provider built in (v2.2.4 or newer))
  • FortiGate with FortiOS v7.2.8 Special Build 9127 (has the Securosys PKCS#11 Provider built in (v2.3.2 or newer))
  • An HSM:

Get an HSM

CloudHSM is a hosted offering from Securosys, where Securosys manages the HSMs for you in a geo-redundant cluster.

For testing purposes, CloudHSM offers a free 90-day trial.

Sign up to CloudHSM

Configure the HSM

info

You can skip this step if you are using CloudHSM.

If you are using an on-premise HSM, start by installing the hardware. Run through the Initial Wizard, set up your Genesis and Security Officer (SO) roles, and define the network settings.

Once this basic HSM setup is done, proceed with necessary configurations to integrate Fortinet, as explained below.

Create a Partition

Create a new Partition. The Fortinet appliance will use this Partition to store its keys.

Roles User Create

Enable PKCS#11 API

The PKCS#11 API must be enabled on the device and user (partition) level.

  • Setup Configuration Security Device Security Crypto Policy PKCS#11: enabled
  • Setup Configuration Security User Security (user name) PKCS#11: enabled

Set PKCS#11 Password

Assuming that user level configuration is used.

  • Setup Configuration Security User Security (user name) PKCS#11 password

Generate a New Setup Password

Generate a new setup password for the partition:

  • Roles User New Setup Pw

Disable Wrapped Key Export, Key Extract, and Key Import

  • Setup Configuration Security User Security (user name) Key export: disabled
  • Setup Configuration Security User Security (user name) Key extract: disabled
  • Setup Configuration Security User Security (user name) Key import: disabled
Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?