Architecture overview

An AWS XKS protected by the nShield HSM was deployed for this integration testing. The AWS XKS has a public domain name and a publicly trusted certificate. The Delinea Platform connects to the AWS XKS using shared secrets.

AWS XKS overview

The AWS XKS consisted of an AWS Linux EC2 instance running the Security World software. The HSM was physically located at an Entrust test lab.

The AWS XKS endpoint was fronted by an AWS Network Load Balancer (NLB). A public DNS record was created. A publicly trusted TLS certificate was issued to connect to the XKS via the NLB.

The deployment of the AWS XKS protected by the nShield HSM is covered in a separate document available at nShield Integration Guides.

Delinea Platform overview

Delinea provided a link via email to register with their platform. A tenant was created through the registration process, which in turn created a URL to access the tenant. Access to the URL is secured using credentials and multifactor authentication.

delinea platform deployment

Connection to the AWS XKS

An encryption key was created in the AWS XKS. An AWS IAM user was created and granted permissions to use the key. The key ARN, the IAM user access key, and the secret access key were shared with the Delinea Platform to establish a connection to the AWS XKS.