Entrust nShield HSM for SSL Decryption for iSSL

The purpose of this feature is to provide the capability for inline-SSL feature to work with HSM hardware. Some enterprises where security is paramount use nCipher HSM to keep the sensitive information such as private keys safe. For the deployments that involves HSM, changes need to be made for how the keys are used during session establishment for inline-ssl feature.

Supported Platforms

■   GigaVUE HC1
■   GigaVUE HC1-Plus
■   GigaVUE HC3

 

PKCS#11 Library

The PKCS#11 (Public Key Cryptography Standards) is a standard programming interface to communicate with HSMs. This standard specifies an application programming interface (API), called “Cryptoki” to devices which hold cryptographic information and perform cryptographic functions.

Proprietary interfaces using Secure Object Library are provided to interact with the HSM for:

■   Generating key pair within the HSM.
■   Installing existing key in the HSM.
■   Manufacturing Protection key operations.

 

Refer to Configuring Inline SSL with HSM for Key Management for more details.