Key Store Management

Steps to create, manage, and delete Key Stores.

Creating Key Stores

The steps to create a Key Store depend on the type, as shown in the following table.

Only users with a Security Administrator privileges can create Key Stores.

Key Store TypeSteps to Create Key Store
PKCS #11
AWS KMSConfiguring the ESA with AWS KMS
Google Cloud KMSConfiguring the ESA with Google Cloud KMS
Azure Key Vault Managed HSMConfiguring the ESA with Azure Key Vault Managed HSM

Managing Key Stores

A user with Security Administrator privileges can fully modify Key Stores after they have been created. However, a user with Security Viewer privileges cannot modify Key Stores.

Deleting Key Stores

Only a user with Security Administrator privileges can delete Key Stores. However, an active Key Store cannot be deleted. Also, the default Protegrity Soft HSM cannot be deleted.

To remove a Key Store:

  1. On the ESA Web UI, navigate to Key Management > Key Stores.

    The Key Stores tab appears.

  2. Select the name of a key store from the list, and click the Delete action.

    A confirmation dialog box appears.

  3. Click OK.

    A message Key Store has been deleted successfully appears.


Support Matrix

Support Matrix for the Hardware Security Module (HSM) and cloud platforms.

Configuring the ESA with HSMs supporting PKCS#11 Interface

Steps to connect to PKCS #11 HSMs.

Configuring the ESA with the Thales Luna HSM

Steps to connect to the Thales Luna HSM.

Configuring the ESA with Thales Data Protection on Demand (DPoD) HSM

Steps to connect to Thales DPoD HSM.

Configuring the ESA with AWS Key Management System (KMS)

Steps to connect to AWS KMS.

Configuring the ESA with Google Cloud KMS

Steps to connect to Google Cloud KMS.

Configuring the ESA with Azure Key Vault Managed HSM

Steps to connect to Azure Key Vault Managed HSM.

Switching Key Stores

Steps to switch Key Stores.

Troubleshooting

Steps to troubleshoot HSM integration issues.

TAC Replication of Key Store-specific Files and Certificates

Steps to perform TAC replication of Key Store-specific files and certificates.


Last modified : October 31, 2025