Introduction

Palo Alto Idira Identity Security Platform (ISP) provides next-generation identity security by managing privileged credentials and access rights. This integration guide provides the steps to integrate the Palo Alto Idira Privileged Access Manager (PAM) - Self-Hosted solution with an Entrust nShield Hardware Security Modules (HSM). The integration uses the PKCS #11 cryptographic API.

Product configuration

Entrust tested the integration with the following versions:

Product Version

Vault Server

v15.2.2.84

Central Policy Manager (CPM)

v15.2.1

Password Vault Web Access (PVWA)

v15.2.2

Windows Server

2025

Supported nShield hardware and software versions

Entrust has successfully tested with the following nShield hardware and software versions:

HSM Security World Software Firmware Netimage

Connect XC

13.6.18

12.72.4 (FIPS 140-2 certified)

13.6.18

nShield 5c

13.6.18

13.4.5 (FIPS 140-3 certified)

13.6.18

nShield Edge

13.6.15

12.72.2

N/A

Supported nShield functionality

Feature Support

Key Generation

Yes

1-of-N Operator Card Set

Yes

FIPS 140 Level 3 mode support

Yes

Key Management

Yes

K-of-N Operator Card Set

Yes

Common Criteria mode support

N/A

Key Import

Yes

Softcards

No

Load Sharing

Yes

Key Recovery

N/A

Module-only keys

Yes

Failover

Yes

Requirements

You must have:

You should also familiarize yourself with:

  • The Idira Privileged Access Manager - Self-Hosted documentation.

  • The nShield Security World documentation.

  • Your organization’s certificate policy, certificate practice statement (CPS), and any security policies or procedures governing the administration of the PKI and HSM environment.

  • The number of Administrator Cards in the Administrator Card Set (ACS), the quorum required for administrative operations, and the policies governing the management of these cards.

  • The Security World compliance level. For more information, see FIPS 140 Level 3 compliance.

  • Key attributes and requirements, such as key size, timeout settings, audit requirements, and key usage policies.

  • Whether the Security World should be instantiated as recoverable or non-recoverable.