Skip to main content

Prerequisites

To install CyberVault KMS, you need:

System Requirements

Every container in the Key Manager (excluding the auth container) has the following minimum requirements:

  • CPU: 0.5
  • RAM: 256 MB

The auth container has higher requirements because it caches more runtime state in memory:

  • CPU: 1 (recommended 2)
  • RAM: 2048 MB

Configuring the HSM

First, make sure that the Root Key Store is set up.

In the User Security Configuration of your Partition, enable User Configuration, JCE, and REST API.

User Config -> Edit -> (setting)

Enable:

  • User Configuration
  • JCE
  • REST API
  • Key import (for on-prem TSB and mTLS)
note

Key import needs to be enabled temporarily for installations that use an on-prem TSB with mTLS as the authentication method.

The installer imports an issuing CA key into the HSM (by default kms.tsb.user.ca), which issues the TSB client certificates. Without key import, the installer stops with KeyImportNotAllowed.

Key import is only used during this bootstrap and can be disabled afterwards. Re-enable key import if you reinstall the KMS from scratch or restore a backup (as that generates a new CA key).

info

In CloudHSM, these options are enabled by default.

Optional Features

Additionally, if you use one of the following features, enable their respective config option:

License / Config OptionDescription
KM SystemEnhanced Authentication Subscription, including: unlimited users, SSO, TOTP.
KMI ProtocolRequired to run the KMIP Server
"Key Authorization". Optionally: "TSB Workflow Engine"Smart Key Attributes and Approver Management
info

In CloudHSM, please request these features to be enabled. Either during ordering, or by opening a support ticket later.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?