Introduction

This document describes how to integrate the Delinea Platform with the AWS Key Management Service (KMS) External Key Store (XKS) supported by the Entrust nShield Hardware Security Module (HSM).

Product configurations

Entrust has successfully tested nShield HSM integration in the following configurations:

Product Version

Delinea Platform

12.1.000024

Supported nShield hardware and software versions

Entrust has successfully tested with the following nShield hardware and software versions:

HSM Security World Software Firmware Netimage

Connect 5c

13.9.5

13.8.4

13.9.5

nShield XC

13.9.5

13.8.3

13.9.5

Supported nShield features

Entrust has successfully tested nShield HSM integration with the following features:

Feature Supported

Module Only Key

Yes

nSaaS

Supported but not tested

Requirements

  • Access to Delinea Platform from your Delinea sales representative.

  • Access to the Entrust TrustedCare Portal.

  • Access to an AWS XKS (External Key Store) supported by the Entrust nShield Hardware Security Module (HSM).

Familiarize yourself with the nShield Documentation.

  • The importance of a correct quorum for the Administrator Card Set (ACS).

  • Whether your Security World must comply with FIPS 140 Level 3 or Common Criteria standards. For more information, see FIPS 140 Level 3 compliance.

  • Whether to instantiate the Security World as recoverable or not.