DuoKey Azure EKM Proxy
Let Azure Managed HSM wrap and unwrap Customer-Managed Keys with a key held in your DuoKey vault
What is Azure EKM?
Azure's External Key Manager (EKM) protocol lets Azure Managed HSM delegate the wrap and unwrap of a Data Encryption Key (DEK) to a key manager you run, instead of storing the Key Encryption Key (KEK) inside Azure. Azure services configured with a Customer-Managed Key on top of Managed HSM — such as Azure SQL Database Transparent Data Encryption (TDE) or column-level encryption — call the EKM endpoint every time they need to protect or recover a DEK.
DuoKey Cockpit implements this protocol (API version 0.1-preview) as a built-in app: DuoKey acts as the EKM proxy, and the KEK never leaves your DuoKey vault.
Azure calls the mTLS-terminated Cockpit endpoint for every wrap/unwrap; the KEK itself never leaves your tenant vault.
Wrap / Unwrap
Azure sends the DEK to be wrapped or unwrapped with your KEK — the KEK itself is never exposed to Azure
Mutual TLS
Every request is authenticated with a client certificate that must chain to a CA you configure
Algorithm Choice
AES Key Wrap (with or without padding) for AES-256 keys, or RSA-OAEP-256 for RSA keys
Self-Test & Health
Built-in wrap/unwrap round-trip test and a structured health check for the endpoint
How it fits the Cockpit Apps model
Like DuoKey's other integrations, the Azure EKM proxy is an App deployed from the Cockpit Apps catalog — there is nothing to install separately. You deploy an EKM endpoint from the same interface you use to manage your other apps and keys, and the endpoint is bound to a single vault and key you select during deployment.
Supported algorithms
| Algorithm | Key type | Description |
|---|---|---|
A256KW | AES-256 | AES Key Wrap (RFC 3394) |
A256KWP | AES-256 | AES Key Wrap with Padding (RFC 5649) — for arbitrary-length plaintext |
RSA-OAEP-256 | RSA-2048 / RSA-4096 | RSA-OAEP with SHA-256 |
For AES algorithms, the wrap/unwrap is performed using the raw KEK fetched from your vault. For RSA-OAEP-256, the operation is delegated to the vault adapter instead, so an HSM-backed RSA private key never leaves the vault.
How it works
Azure needs to protect or recover a DEK
Azure Managed HSM (or an Azure service configured with a Managed HSM Customer-Managed Key, such as Azure SQL TDE) needs to wrap a new DEK, or unwrap a previously wrapped one.
Azure calls your EKM proxy over mTLS
Azure presents a client certificate on every request. If mutual TLS is required for the endpoint (the default), DuoKey verifies the certificate chains to the client CA you configured and, if you pinned an expected Subject CN, that the certificate's CN matches it.
DuoKey resolves the endpoint's key
The unguessable endpoint path (its slug) resolves to the vault and key you selected when you deployed the endpoint — the Key Encryption Key.
Wrap or unwrap runs against the KEK
For A256KW/A256KWP the operation runs against the KEK's raw key material fetched from the vault; for RSA-OAEP-256 it is delegated to the vault so the private key never leaves it.
Result returned to Azure
The wrapped (or unwrapped) key bytes are returned to Azure over the same mTLS connection. If audit logging is enabled on the key, the operation is recorded in DuoKey's audit trail.
Endpoints created on deployment
Deploying an Azure EKM app creates one endpoint, identified by an auto-generated slug, under /azureekm/<slug>:
| Operation | Path | Purpose |
|---|---|---|
| Proxy info | POST /azureekm/{slug}/info | Returns proxy identification, used by Azure to discover the endpoint |
| Key metadata | POST /azureekm/{slug}/{key_name}/metadata | Returns key type, size and supported operations (and, for RSA keys, the public modulus/exponent) |
| Wrap | POST /azureekm/{slug}/{key_name}/wrapkey | Encrypts a DEK with the KEK |
| Unwrap | POST /azureekm/{slug}/{key_name}/unwrapkey | Decrypts a previously wrapped DEK |
| Health | GET /azureekm/{slug}/health | Simple health check for monitoring |
These endpoints authenticate Azure with mutual TLS and the unguessable slug — not a user session or JWT. The slug is generated when you deploy the endpoint and should be treated as a credential.
Key features
Mutual TLS
Client CA validation with optional Subject CN pinning to a specific Managed HSM identity
AES & RSA algorithms
A256KW, A256KWP, and RSA-OAEP-256 — restrict which are allowed per endpoint
Vault-backed KEK
The key never leaves your DuoKey vault; RSA private keys never leave it even during wrap/unwrap
Self-test
One-click wrap/unwrap round trip — against the real key for an AES-256 KEK, or a synthetic plumbing check otherwise; the endpoint health check exercises the real key for RSA too
Structured health check
Verifies deployment, key availability, wrap/unwrap, and mTLS configuration in one call
Audit logging
Wrap and unwrap operations are recorded when audit logging is enabled on the key
Use cases
Azure SQL TDE
Protect SQL Database Transparent Data Encryption keys with a KEK you control, outside Azure Managed HSM.
Column-level encryption
Use the same externally-held KEK for Always Encrypted / column-level encryption scenarios built on Managed HSM CMK.
Key sovereignty
Keep the key-encryption key under your own control while Azure continues to manage the encrypted data.
Instant revocation
Disable the endpoint or the key in DuoKey and Azure immediately loses the ability to wrap or unwrap.
Prerequisites
المتطلبات المسبقة
- An Azure Managed HSM (or Azure service backed by one) configured for Customer-Managed Keys / External Key Manager
- The client CA certificate that issues Azure's client certificate for the EKM connection
- A DuoKey vault with an AES-256 key (for A256KW/A256KWP) or an RSA-2048/4096 key (for RSA-OAEP-256)
- DuoKey Cockpit admin access with permission to manage Apps