Skip to main content

Prerequisites

Make sure to adhere to the following prerequisites before continuing with integrating Securosys Primus HSM or CloudHSM with Salesforce BYOK.

Salesforce Organization Configuration

You need to set up your Salesforce Organization before being able to use Salesforce BYOK. This includes:

  • Salesforce account with Enterprise, Performance, or Unlimited Edition subscription with Salesforce Shield enabled,
  • Either Salesforce Classic or Lightning Experience,
  • Salesforce User Permissions Manage Encryption Keys, Manage Certificates and Customize Application.

Primus HSM Configuration

You will need either a Securosys Primus HSM or a CloudHSM subscription.

For on-premise Primus HSMs, the following setup steps are required:

  1. Complete the Initial Wizard to get the HSM into a basic operational state.
  2. Create an HSM Partition where Salesforce will store its keys.
  3. Note down the Setup Password of your Partition (or create a new one).
  4. Make sure that the following config options are enabled, both on the device-level and on the partition-level:
    • JCE API
    • Key export
    • Key extraction

For detailed instructions on how to perform these tasks, please see the Primus HSM User Guide.

Primus Tools

Install the Securosys Primus Tools on a local computer. You will use the Primus Tools to securely transfer the key material from the HSM to Salesforce.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?