Skip to main content
Applies to:
Cockpit v2Sepior / Blockdaemon TSMThreshold MPC

Overview​

Sepior (now part of Blockdaemon) provides a threshold MPC / TSM (Threshold Signature Module) vault: each key is split into shares across multiple nodes, and no single node ever holds the complete key. Cryptographic operations are computed jointly across the nodes.

In Cockpit v2 this backend does not talk to the TSM nodes directly — it proxies through the DuoKey KMS API, which brokers the MPC session and operations.

PropertyValue
Vault typesepior_mpc
ModelThreshold MPC (key shares across TSM nodes)
IntegrationVia the DuoKey KMS API (not direct to TSM)
Post-quantumNot supported (classical algorithms only)

How it connects​

1

Obtain an OAuth2 token

The adapter authenticates to the configured identity provider (Azure AD v1/v2 supported) using client credentials.

2

Initialize a KMS session

It calls the DuoKey KMS API to initialize a session, passing the Sepior TSM credentials as signed credentials alongside the bearer token.

3

Run crypto operations

Create, encrypt/decrypt, sign/verify and delete are executed through the KMS API against the MPC key shares.

Configuration​

FieldPurpose
token_endpointOAuth2 token endpoint (Azure AD v1/v2 supported)
client_idOAuth2 client id
client_secretOAuth2 client secret (encrypted at rest, zeroized in memory)
scopeOptional OAuth2 scope
vault_credentialsRequired Sepior TSM credentials (user id, node passwords, node URLs)

The vault id is injected automatically so the KMS API routes to the correct key set. Secrets and cached tokens are zeroized from memory when no longer needed. If the backend's API rate-limit is exceeded, the call fails immediately with a rate-limit error rather than being retried.

What it supports​

CapabilityDetail
SymmetricAES-128 / AES-256
RSARSA-2048 / RSA-4096
ECCEC-P256 / EC-P384
MACHMAC
Operationscreate, delete, encrypt, decrypt, sign, verify, public-key, key info, key count
Post-quantumNot supported — use the Software Vault or Securosys for PQC
Key listing

Keys created through this backend are tracked in the Cockpit database rather than enumerated from the TSM, so remote key listing is served from Cockpit; a remote count is available for reconciliation.

Why MPC

Both the Sepior vault and the DuoKey MPC KMS remove the single-point-of-compromise of a monolithic key store. For the rationale behind multi-party computation, see Why MPC.