Configuring KeyControl as an HSM Client using nCipher nShield Connect
The following procedure describes how to configure KeyControl as an nCipher nShield Connect HSM client. You can either use a standalone KeyControl node or a cluster.
Before You Begin
For the nCipher nShield Connect HSM server that you want to connect to KeyControl, make sure you have the following information available:
- The HSM Server Name, Server IP/FQDN, ESN, Port, and Keyhash.
- The Security World Bundle file that is provided by the HSM Administrator.
-
Information to create a softcard consisting of a label and password.
You will also need:
- A KeyControl account with Security Admin privileges.
-
If you are using an on-premise HSM server, you must have access. .
Procedure
-
Log into the KeyControl webGUI using an account with Security Admin privileges.
Note: If you are using a cluster, you only need to use the webGUI for one node.
- In the top menu bar, click Settings.
- In the System Settings section, click HSM Server Settings.
-
On the HSM Server Settings tab, select nCipher nShield Connect HSM.
The nCipher nShield Connect HSM Server Settings window displays the information you will need to continue.
- Click the Copy the IP address and keyhashes to the keyboard link and paste them in a text window.
-
Use the IP address and keyhash to authenticate KeyControl on nShield. Please see your nShield documentation.
Important: For KeyControl clusters, you will need to authenticate the IP address and keyhash for each KeyControl cluster node.
- Copy the Security World Bundle from nShield and place it on your local machine. It should be in the format world.zip.
- After reading the Get Started Screen, click Continue.
-
On the Enrollment screen, complete the following:
Note: All information is from the nShield HSM. The Server Name is used for display purposes and the Server IP/FQDN is used for communication.
Field
Description
Server Name
Enter the FQDN of the nShield HSM.
Server IP/FQDN
Enter the IP address or FQDN for the nShield HSM.
Server ESN
Enter the nShield Electronic Serial Number (ESN).
Type
Select the location of the nShield HSM. This can be On Prem or Cloud.
Port
Enter the port used for the nShield HSM.
Keyhash
Enter the keyhash of the nShield HSM.
- Click Enroll and Continue.
- On the Security World screen, click Load File and locate the security world bundle that you downloaded from the nShield HSM.
- Click Upload and Continue.
-
On the Softcard screen, enter the Softcard Label and Softcard Password that you want to use to link to the HSM server.
-
Click Complete Setup.
After the setup is complete, you will be returned to the nCipher nShield Connect HSM Server Settings page.
Note: If the configuration failed, then you must select Actions > Reset HSM Configuration before you try again.
-
Select Actions > Test Connection from the Basic tab to ensure that the HSM is fully connected to KeyControl.
What to Do Next
-
If you want to use nShield Connect HSM to store your Admin Key, you will need to restore it. See Generating the Admin Key.
The new Admin Key is automatically stored in the nShield HSM. Click Locate Admin Key in the nShield Connect HSM Server Settings page to view.
- If you want to form a KeyControl cluster using the nShield Connect HSM, see Configuring a KeyControl Cluster using nCipher nShield Connect HSM Client.
- If you want to use an additional nShield Connect HSM for a high availability cluster, see Configuring an nCipher nShield HSM for High Availability .