HSM Agent (On-Prem HSM)
Bring your own on-premises HSM into Cockpit — key material never leaves your hardware, and no inbound connection is ever required.
Overview
The HSM Agent vault type lets you connect an HSM you already own and operate on your own premises to Cockpit, without the HSM ever being reachable from the internet. A small, hardened agent process is installed next to your HSM. It opens an outbound-only encrypted tunnel to Cockpit — your network never needs an inbound firewall rule, and the HSM is never directly exposed.
Once connected, keys that physically live on your HSM show up in Cockpit as an ordinary vault: they can be inventoried, governed by access policy, and used for key lifecycle management (create, rotate, retire) and cryptographic operations such as sign, verify, encrypt and decrypt — while the key material itself never leaves your HSM.
The tunnel is always initiated by the agent — your network never opens an inbound rule, and the HSM is never directly exposed.
| Property | Value |
|---|---|
| Vault category | On-prem HSM, bring-your-own hardware |
| Connectivity | Outbound-only from the customer network |
| Key custody | Stays on the customer's HSM — never transits to Cockpit |
| Authorization model | Three independent gates per operation (see below) |
| Audit | Tamper-evident, hash-chained log stored on-premises |
DuoKey never holds, sees, or can export the private or symmetric key material behind an HSM Agent vault. Every cryptographic operation is executed on your HSM, by the agent, under a policy your organization controls.
Supported HSM vendors
Securosys remains DuoKey's preferred, lead HSM partner. The HSM Agent additionally supports connecting to several other vendors' on-premises hardware:
| Vendor | Notes |
|---|---|
| Securosys | DuoKey's preferred HSM partner; also available as a directly-managed vault — see Securosys HSM |
| Thales | Supported on-premises HSM |
| Entrust | Supported on-premises HSM |
| Utimaco | Supported on-premises HSM |
| Eviden (Atos) | Supported on-premises HSM |
The agent talks to your HSM through the vendor's standard cryptographic interface module, so any HSM offering a compatible interface for your vendor is a candidate — check with your DuoKey contact to confirm certification for your specific model and firmware.
How it connects
Install the agent
A hardened agent process is installed on a host with access to your HSM (on the same network segment, no internet exposure required for the HSM itself).
Enroll
The agent is enrolled against Cockpit using a short-lived, single-use enrollment credential issued from the Cockpit console. Enrollment binds the agent to your tenant and to the vault it will serve.
Open the outbound tunnel
The agent initiates and maintains an encrypted, authenticated tunnel outbound to the Cockpit gateway. No inbound rule is ever opened on your side, and the connection is proxy-friendly.
Approve the agent
An administrator reviews the agent's identity in Cockpit and approves it before it is allowed to perform any operation — a human confirms the agent that connected is the one that was expected.
Use it as a vault
Once approved and governed by policy, the HSM Agent vault behaves like any other Cockpit vault: keys can be created, inventoried, rotated, retired, and used for cryptographic operations such as sign, verify, encrypt and decrypt.
Three-gate authorization model
Because the HSM stays fully under your control, Cockpit cannot simply "tell" it what to do. Every operation the agent is asked to perform must pass three independent checks before it ever touches the HSM — compromising any single one of them is not enough to run an operation:
The agent enforces all three gates itself — even when the link to Cockpit is down — so a compromised gateway account alone is never enough.
1. Authenticated tunnel
The channel between the agent and Cockpit is authenticated with a credential unique to that agent and encrypted end to end. An unauthenticated caller cannot reach the agent at all.
2. Signed access policy
The agent enforces a locally cached, cryptographically signed policy — authored and versioned in Cockpit — that says which principals may perform which operations, on which keys, under which conditions. The agent enforces this policy itself, even if the network link to Cockpit is down.
3. Per-operation authorization token
Each individual operation additionally requires a fresh, short-lived, single-use token minted by Cockpit at the moment of the request. A stale or replayed token is rejected.
If any one of the three gates cannot be verified — the tunnel is not authenticated, the cached policy is missing or stale, or the per-operation token is invalid or expired — the agent refuses the operation. Cockpit cannot silently ask your on-prem HSM to do something outside its granted policy.
Local, tamper-evident audit log
The agent keeps its own hash-chained audit log of every operation it performs — accepted and denied — stored on your premises. Each entry is chained to the previous one, so any attempt to alter or remove a past entry breaks the chain and is detectable, independently of Cockpit's own copy of events.
Because the audit log lives on your own infrastructure, your security and compliance teams retain an independent, locally verifiable record of every operation performed against your HSM — not just DuoKey's copy of it.
Configuration concept
The agent is configured through a local configuration file on the agent host, together with a small number of protected values. Conceptually, the configuration covers:
| Setting | Purpose |
|---|---|
| Gateway address | The Cockpit endpoint the agent connects outbound to |
| Agent identity / API key | Assigned during enrollment; identifies this agent to Cockpit |
| Policy-signing public keys | Used by the agent to verify that a policy update genuinely came from Cockpit before trusting it |
| HSM interface module path | The path to your HSM vendor's cryptographic interface module on the agent host |
| Target HSM slot | Which slot on the HSM the agent should operate against |
| HSM PIN | Required to open a session on the HSM; can be supplied in the configuration file or via a protected environment variable instead |
The HSM PIN is a secret that stays entirely on the agent host. It is used locally to open a session on your HSM and is never transmitted to, or recoverable from, Cockpit.
Deployment tiers
The HSM Agent's tunnel can connect to Cockpit at more than one deployment tier, so the level of connectivity to DuoKey can match your organization's security posture:
| Tier | Description | Typical fit |
|---|---|---|
| SaaS-connected | Cockpit runs as DuoKey SaaS; the agent tunnels outbound to it over the internet | Standard deployments |
| Customer-hosted Cockpit | Cockpit itself is deployed on your premises; the agent tunnels to your own local Cockpit instance | Organizations that keep the full control plane on-premises |
A fully air-gapped mode — no live network link at all, with policy updates and audit exports moved by signed offline artifacts — is planned for a future release. Today the agent requires a live outbound tunnel to a Cockpit control plane, whether that Cockpit is DuoKey-hosted or deployed on your own premises.
Capabilities once connected
Key inventory
Keys already on your HSM, and keys created through Cockpit, are visible and discoverable as part of the vault.
Access policy
Standard Cockpit access policy governs which applications and users may use which keys, on top of the agent's own local policy enforcement.
Key lifecycle management
Create, rotate and retire keys on your HSM through the same lifecycle flows used for any other vault.
Cryptographic operations
Sign, verify, encrypt and decrypt with keys on your HSM through the agent's curated operation set, under the same access policy as any other vault backend.