Skip to main content

Multitenancy (KMS)

CyberVault KMS supports multitenancy, meaning that one installation can serve multiple HSM Partitions.

Base Partition

The Base Partition is the first Partition that operators add during the KMS installation flow. The KMS stores its own state in the Base Partition as HSM data objects. For more details, see the state documentation.

Additional Partitions

Operators can add additional Partitions. Once added, they can be managed through the Key Manager UI with the same set of features.

To add a Partition, you need the Admin role on the Key Manager UI. For on-premise Primus HSM you also need operator access to the KMS installation.

  1. Install the TSB.
    • For an on-premise HSM Partition, install an additional TSB. Skip this step if you used CloudHSM.
    • As an operator, run keymanager add-tsb to deploy an additional TSB. You will be asked to provide the HSM details (host, port, Partition name, Setup Password).
  2. Add the Partition to the Key Manager UI.
    • As an administrator, go to Settings > HSM Partitions > Register HSM Partition.
    • Follow the wizard.
    • You will be asked for the TSB details (URL, JWT or mTLS client certificate).
    • You will be asked whether to configure KMIP for this Partition and to assign users to the Partition. Both of these can also be done later.

Your Partition should now show up under Settings > HSM Partitions. From there, you can edit the Partition settings (TSB URL, JWT, assigned users, ...).

tip

The additional Partitions don't need to be on the same HSM cluster as the Base Partition. It is possible to manage both CloudHSM Partitions and on-premise HSM Partitions through a single CyberVault KMS installation.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?