Integrating Secret Server with a SafeNet HSM
To integrate Delinea Secret Server with the SafeNet HSM, complete the following steps in each section.
Task 1: Setting up Secret Server
Install Delinea Secret Server on the target machine. See Installation for detailed installation instructions.
Task 2: Configuring the SafeNet KSP
To configure the SafeNet Key Storage Provider (KSP):
- Go to the
SafeNet HSM Client installation Directory\KSP
directory. If using an HSMoD service, the KSP folder is available in the service client package. - Double-click
KspConfig.exe
. The SafeNet KSP configuration wizard displays. - Double-click Register or View Security Library on the left side of the pane.
- Click Browse.
- Select a cryptographic library, such as SafeNet HSM Client installation Directory\cryptoki.dll.
- Click Register.
- If using an HSMoD service, the cryptographic libraries are available in the service client package. On successful registration, a message "Success registering the security library" displays.
- Double-click Register HSM Slots on the left side of the pane.
- Type the Slot (Partition) password.
- Click Register Slot to register the slot for Domain\User. On successful registration, a message "The slot was successfully and securely registered" displays.
- Register the same slot for NT_AUTHORITY\SYSTEM.
- If using the HSMoD service, place SafeNetKSP.dll in C:\Windows\System32.
- Restart the IIS after registering KSP for changes to take effect.
Task 3: Enabling the HSM
- Go to the Admin menu and click Configuration.
- Select the HSM tab. This starts the HSM wizard, which guides the process of selecting the HSM’s CNG provider.
- Click Enable HSM.
- The HSM Setup screen displays providing information about HSM integration.
- Click Next.
- Select SafeNet Key Storage Provider from Persistent Provider drop down box under HSM Providers section.
- Select key size of RSA from Key size drop down box.
- Click Next. Once SafeNet Key Storage Provider is selected, Secret Server stimulates encryption and decryption operations.
- Verify the results to ensure its functioning properly.
- The HSM Providers Test Results section shows the result Success.
- Click Next.
- The HSM Verify Configuration page displays. Review HSM configuration.
- Click Save.
- The HSM Setup Complete page displays message "The HSM is now enabled.”
- Click Finished.
Task 4: Verifying the Integration
- Restart the IIS for configuration changes to take effect. The HSM configuration is saved and can now be viewed under the HSM tab.
- The Secret Server encryption key is now stored on SafeNet HSM partition.
- Verify the key using the lunacm utility. This completes the integration of DelineaSecret Server with SafeNet Luna HSM or SafeNet Data Protection on Demand Service.