Platform Capabilities
The cryptographic surface of Cockpit v2 — a native KMIP server, unified vault and HSM adapters, a full PKI stack, and post-quantum readiness tooling.
KMIP server
Cockpit v2 embeds a native KMIP 2.x server — OASIS TTLV encoding over TLS — listening on port 5696. Clients can consume keys over the standard KMIP protocol without any DuoKey-specific SDK.
| Property | Value |
|---|---|
| Protocol | KMIP 2.x |
| Encoding | OASIS TTLV over TLS |
| Listener port | 5696 |
| Access | Standard KMIP clients — keys consumed over the wire |
Vault and HSM adapters
Sixteen backends sit behind a single, uniform interface. Every backend exposes the same operations, so applications and services work the same way regardless of where the key material actually lives.
Uniform operations
Every backend supports the same operations: create, rotate, destroy, encrypt, decrypt, sign, verify, wrap, unwrap and health checks.
Per-tenant credentials
Backend credentials are stored encrypted per tenant, so each tenant can bind to its own HSM or KMS instance.
| Backend | Type / notes |
|---|---|
| DuoKey KMS | Software MPC — default backend |
| Securosys | Primus / CloudsHSM |
| AWS KMS | Cloud KMS |
| Azure Key Vault | Cloud KMS |
| GCP KMS | Cloud KMS |
| Alibaba Cloud KMS | Cloud KMS |
| HashiCorp Vault | Software vault |
| OpenBao | Software vault |
| Fortanix SDKMS | HSM / KMS |
| Utimaco | PKCS#11 |
| Atos TrustWay | PKCS#11 |
| Thales Luna | PKCS#11 |
| Crypto4A | HSM |
| Sepior | MPC |
| Software | In-memory (dev) |
| On-Prem HSM (Agent) | Customer-owned HSM, bring-your-own hardware |
The lead hardware security module partner for Cockpit v2 is Securosys (Primus / CloudsHSM). Cloud KMS backends and the PKCS#11 HSMs (Atos TrustWay, Thales Luna, Utimaco) are also supported through the same adapter interface.
Secret managers
For application secrets — as distinct from cryptographic key material — Cockpit v2 integrates with the following secret managers:
| Secret manager |
|---|
| HashiCorp Vault |
| OpenBao |
| AWS Secrets Manager |
| Azure Key Vault |
| GCP Secret Manager |
CyberArk Conjur, Thycotic Secret Server and Infisical are planned secret-manager integrations and are not yet available.
PKI
Cockpit v2 provides a complete public-key infrastructure: a full certificate authority hierarchy, template-based issuance, and broad enrollment-protocol coverage.
CA hierarchy
A full chain — Root, then Intermediate, then Issuing CA — with template-based X.509 certificate issuance and multiple certificate issuers.
Protocol support
ACME (RFC 8555), EST, SCEP, CMP, OCSP and CRL, plus KMIP for key delivery.
Kubernetes
Integrates with cert-manager so Kubernetes workloads can request and renew certificates natively.
| Capability | Detail |
|---|---|
| CA hierarchy | Root -> Intermediate -> Issuing |
| Issuance | Template-based X.509, multiple certificate issuers |
| Enrollment protocols | ACME (RFC 8555), EST, SCEP, CMP, KMIP |
| Validation / revocation | OCSP, CRL |
| Kubernetes | cert-manager integration |
Post-quantum
DuoKey's post-quantum tooling is a quantum-readiness toolset for discovering, scoring and planning the migration of cryptographic assets. It scans TLS handshakes and X.509 certificates, produces a cryptographic bill of materials, and grades quantum exposure.
Discovery
TLS-handshake and X.509 scanning, with an sslyze-parity SSL audit.
CBOM
A CycloneDX 1.7 cryptographic bill of materials (CBOM) inventorying discovered cryptography.
Quantum Risk Score
A 4-signal Quantum Risk Score (QRS) grading each asset's exposure to quantum attack.
Migration planning
Break-year migration planning aligned to NIST IR 8413 and CNSA 2.0.
PQC primitives use the FIPS standards: ML-KEM, ML-DSA and SLH-DSA.
| Component | Detail |
|---|---|
| Scanning | TLS-handshake + X.509 scanning |
| CBOM | CycloneDX 1.7 cryptographic bill of materials |
| Quantum Risk Score | 4-signal QRS |
| SSL audit | sslyze-parity |
| Migration planning | Break-year planning aligned to NIST IR 8413 / CNSA 2.0 |
| PQC primitives | FIPS ML-KEM / ML-DSA / SLH-DSA |
This page summarizes the post-quantum capabilities embedded in Cockpit v2. For the complete workflow — scanning, CBOM export, QRS interpretation and migration planning — see the dedicated PQC Scanner product guide.