Skip to main content
DomainservicesVault interfaceone API · any backendSoftware Vaultdev / testDuoKey MPC KMSdefault · MPC clusterSecurosys HSMFIPS L3 · PQC in hardwareSepior (Blockdaemon)threshold MPCCloud KMSAzure · AWS · GCPPKCS#11 HSMsAtos · Thales · Utimaco · Crypto4A
One uniform interface — the same operations reach a software vault, an MPC cluster, an HSM or a cloud KMS.
Applies to:
Cockpit v2KMIPPKIPQC

KMIP server​

Cockpit v2 embeds a native KMIP 2.x server — OASIS TTLV encoding over TLS — listening on port 5696. Clients can consume keys over the standard KMIP protocol without any DuoKey-specific SDK.

PropertyValue
ProtocolKMIP 2.x
EncodingOASIS TTLV over TLS
Listener port5696
AccessStandard KMIP clients — keys consumed over the wire

Vault and HSM adapters​

Sixteen backends sit behind a single, uniform interface. Every backend exposes the same operations, so applications and services work the same way regardless of where the key material actually lives.

Uniform operations

Every backend supports the same operations: create, rotate, destroy, encrypt, decrypt, sign, verify, wrap, unwrap and health checks.

Per-tenant credentials

Backend credentials are stored encrypted per tenant, so each tenant can bind to its own HSM or KMS instance.

BackendType / notes
DuoKey KMSSoftware MPC — default backend
SecurosysPrimus / CloudsHSM
AWS KMSCloud KMS
Azure Key VaultCloud KMS
GCP KMSCloud KMS
Alibaba Cloud KMSCloud KMS
HashiCorp VaultSoftware vault
OpenBaoSoftware vault
Fortanix SDKMSHSM / KMS
UtimacoPKCS#11
Atos TrustWayPKCS#11
Thales LunaPKCS#11
Crypto4AHSM
SepiorMPC
SoftwareIn-memory (dev)
On-Prem HSM (Agent)Customer-owned HSM, bring-your-own hardware
HSM partner

The lead hardware security module partner for Cockpit v2 is Securosys (Primus / CloudsHSM). Cloud KMS backends and the PKCS#11 HSMs (Atos TrustWay, Thales Luna, Utimaco) are also supported through the same adapter interface.

Secret managers​

For application secrets — as distinct from cryptographic key material — Cockpit v2 integrates with the following secret managers:

Secret manager
HashiCorp Vault
OpenBao
AWS Secrets Manager
Azure Key Vault
GCP Secret Manager
Roadmap

CyberArk Conjur, Thycotic Secret Server and Infisical are planned secret-manager integrations and are not yet available.

PKI​

Cockpit v2 provides a complete public-key infrastructure: a full certificate authority hierarchy, template-based issuance, and broad enrollment-protocol coverage.

CA hierarchy

A full chain — Root, then Intermediate, then Issuing CA — with template-based X.509 certificate issuance and multiple certificate issuers.

Protocol support

ACME (RFC 8555), EST, SCEP, CMP, OCSP and CRL, plus KMIP for key delivery.

Kubernetes

Integrates with cert-manager so Kubernetes workloads can request and renew certificates natively.

CapabilityDetail
CA hierarchyRoot -> Intermediate -> Issuing
IssuanceTemplate-based X.509, multiple certificate issuers
Enrollment protocolsACME (RFC 8555), EST, SCEP, CMP, KMIP
Validation / revocationOCSP, CRL
Kubernetescert-manager integration

Post-quantum​

DuoKey's post-quantum tooling is a quantum-readiness toolset for discovering, scoring and planning the migration of cryptographic assets. It scans TLS handshakes and X.509 certificates, produces a cryptographic bill of materials, and grades quantum exposure.

Discovery

TLS-handshake and X.509 scanning, with an sslyze-parity SSL audit.

CBOM

A CycloneDX 1.7 cryptographic bill of materials (CBOM) inventorying discovered cryptography.

Quantum Risk Score

A 4-signal Quantum Risk Score (QRS) grading each asset's exposure to quantum attack.

Migration planning

Break-year migration planning aligned to NIST IR 8413 and CNSA 2.0.

PQC primitives use the FIPS standards: ML-KEM, ML-DSA and SLH-DSA.

ComponentDetail
ScanningTLS-handshake + X.509 scanning
CBOMCycloneDX 1.7 cryptographic bill of materials
Quantum Risk Score4-signal QRS
SSL auditsslyze-parity
Migration planningBreak-year planning aligned to NIST IR 8413 / CNSA 2.0
PQC primitivesFIPS ML-KEM / ML-DSA / SLH-DSA
Full PQC guide

This page summarizes the post-quantum capabilities embedded in Cockpit v2. For the complete workflow — scanning, CBOM export, QRS interpretation and migration planning — see the dedicated PQC Scanner product guide.