Skip to main content

Prerequisites

Make sure to adhere to the following prerequisites before continuing with integrating Securosys Primus HSM or CloudHSM with Salesforce BYOK.

Salesforce Organization Configuration​

You need to set up your Salesforce Organization before being able to use Salesforce BYOK. This includes:

  • Salesforce account with Enterprise, Performance, or Unlimited Edition subscription with Salesforce Shield enabled,
  • Either Salesforce Classic or Lightning Experience,
  • Salesforce User Permissions Manage Encryption Keys, Manage Certificates and Customize Application.

Primus HSM Configuration​

You will need either a Securosys Primus HSM or a CloudHSM subscription.

For on-premise Primus HSMs, the following setup steps are required:

  1. Complete the Initial Wizard to get the HSM into a basic operational state.
  2. Create an HSM Partition where Salesforce will store its keys.
  3. Note down the Setup Password of your Partition (or create a new one).
  4. Make sure that the following config options are enabled, both on the device-level and on the partition-level:
    • JCE API
    • Key export
    • Key extraction

For detailed instructions on how to perform these tasks, please see the Primus HSM User Guide.

Primus Tools​

Install the Securosys Primus Tools on a local computer. You will use the Primus Tools to securely transfer the key material from the HSM to Salesforce.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?