Architecture overview
AWS XKS overview
An AWS XKS protected by the nShield HSM was deployed for this integration testing. The AWS XKS has a public domain name and a publicly trusted certificate. The Delinea Platform connects to the AWS XKS using shared secrets.
The AWS XKS consisted of an AWS Linux EC2 instance running the Security World software. The HSM was physically located at an Entrust test lab.
The AWS XKS endpoint was fronted by an AWS Network Load Balancer (NLB). A public DNS record was created. A publicly trusted TLS certificate was issued to connect to the XKS via the NLB.
The deployment of the AWS XKS protected by the nShield HSM is covered in a separate document available at nShield Integration Guides.
Connection to the AWS XKS
An encryption key was created in the AWS XKS, protected by a key in the nShield HSM. An AWS IAM user was created and granted permissions to the key in the AWS XKS. The key ARN, the IAM user access key, and the secret access key were shared with the Delinea Platform to establish a connection to the AWS XKS.