Introduction
Palo Alto Idira Identity Security Platform (ISP) provides next-generation identity security by managing privileged credentials and access rights. This integration guide provides the steps to integrate the Palo Alto Idira Privileged Access Manager (PAM) - Self-Hosted solution with an Entrust nShield Hardware Security Modules (HSM). The integration uses the PKCS #11 cryptographic API.
Product configuration
Entrust tested the integration with the following versions:
| Product | Version |
|---|---|
Vault Server |
v15.2.2.84 |
Central Policy Manager (CPM) |
v15.2.1 |
Password Vault Web Access (PVWA) |
v15.2.2 |
Windows Server |
2025 |
Supported nShield hardware and software versions
Entrust has successfully tested with the following nShield hardware and software versions:
| HSM | Security World Software | Firmware | Netimage |
|---|---|---|---|
Connect XC |
13.6.18 |
13.6.18 |
|
nShield 5c |
13.6.18 |
13.6.18 |
|
nShield Edge |
13.6.15 |
12.72.2 |
N/A |
Supported nShield functionality
| Feature | Support |
|---|---|
Key Generation |
Yes |
1-of-N Operator Card Set |
Yes |
FIPS 140 Level 3 mode support |
Yes |
Key Management |
Yes |
K-of-N Operator Card Set |
Yes |
Common Criteria mode support |
N/A |
Key Import |
Yes |
Softcards |
No |
Load Sharing |
Yes |
Key Recovery |
N/A |
Module-only keys |
Yes |
Failover |
Yes |
Requirements
You must have:
-
Access to the Entrust TrustedCare Portal. To request an account, contact nshield.support@entrust.com.
-
Access to the Idira Privileged Access Manager - Self-Hosted software.
You should also familiarize yourself with:
-
The Idira Privileged Access Manager - Self-Hosted documentation.
-
The nShield Security World documentation.
-
Your organization’s certificate policy, certificate practice statement (CPS), and any security policies or procedures governing the administration of the PKI and HSM environment.
-
The number of Administrator Cards in the Administrator Card Set (ACS), the quorum required for administrative operations, and the policies governing the management of these cards.
-
The Security World compliance level. For more information, see FIPS 140 Level 3 compliance.
-
Key attributes and requirements, such as key size, timeout settings, audit requirements, and key usage policies.
-
Whether the Security World should be instantiated as recoverable or non-recoverable.