Configuring HSM encryption in eperi sEcure Platform
Configure the encryption settings for your HSM instance ineperi sEcure Platform.
Before you begin
- Your HSM device/hardware and the HSM client are correctly set up and configured. Please see the topic Connecting a Luna HSM to eperi sEcure Platform for instructions how to do this in case of a Luna HSM.
- You have manually copied the respective "provider" JAR file to the folder
/opt/eperi/gateway/tomcat/webapps/ROOT/WEB-INF/lib.
- For a Luna HSM: LunaProvider.jar
- For a Utimaco HSM: CryptoServerJCE.jar
- Have the credentials of your HSM instance ready. For a Luna HSM those are:
- Provider slot
- HSM password
- HSM partition
- HSM key alias
- For a Utimaco HSM those are:
- HSM device (e.g. 3001@hostname)
- HSM username
- HSM password
- HSM key alias
- HSM key group (optional)
- HSM key specifier (optional)
About this task
Note: In the following, the process is shown using the example of a Luna HSM. For a HSM
of another manufacturer, the procedure is analogous.
Procedure
Results
Important: Please make sure to backup
the encryption keys in your HSM since eperi sEcure Platform only stores a
reference to them!
If you want to use a new HSM key for encryption, you can set up a new key (reference) to the new HSM key and hide the old key (reference) in eperi sEcure Platform. Then the eperi sEcure Platform will still use the old HSM key for decrypting existing values.
Changing the key alias of a key in use either in eperi sEcure Platform or the HSM will result in eperi sEcure Platform not being able to decrypt values anymore which were encrypted with that key!
