Skip to main content

overview

Applications& internal servicesDuoKey Cockpitunified control & auditTransit key backendHashiCorp VaultTransit engine
DuoKey drives HashiCorp Vault as a Transit key backend, so keys and secrets are managed from one console with a single audit trail.
Applies to:
HashiCorp Vault EnterprisePKCS#11 HSM IntegrationAuto-UnsealSeal Wrapping

DuoKey provides seamless PKCS#11 integration with HashiCorp Vault Enterprise, enabling you to auto-unseal your Vault's root key using an AES-256 key managed in your DuoKey Cockpit.

HashiCorp Vault + DuoKey PKCS#11 Architecture

Enterprise-grade HSM-backed secrets management with multi-backend flexibility

Auto-Unseal
HSM-backed
Seal Wrapping
Extra encryption
Entropy Augmentation
True RNG
Root Key Protection
HSM-stored
Requires HSM Integration
▼

HashiCorp Vault Enterprise

Secrets Management
vault.hcl
Configuration
Seal Config
PKCS#11 seal stanza
Secrets Engine
KV, Transit, PKI
Auth Methods
LDAP, OIDC, AppRole
Dynamic SecretsPolicy-Based AccessAudit Logging
PKCS#11 API
▼

Universal PKCS#11 Provider

Seamless integration with multiple vault and HSM backends

PKCS#11 Interface
Standard cryptographic API
Policy Engine
Centralized access control
Backend Router
Flexible backend selection
Audit Trail
Complete operation logging
HSM Operations
Encrypt / Decrypt
Root key ops
Sign / Verify
Seal wrapping
Random Generate
Entropy augmentation
Key Management
Lifecycle control
Secure Channel
▼
DuoKey MPC
Multi-Party Computation
FIPS 140-2 L3
Securosys CloudHSM
Cloud HSM
EU Residency
Azure Key Vault
Cloud KMS
Managed HSM
AWS KMS
Cloud KMS
CloudHSM
Utimaco HSM
Hardware HSM
EAL5+
HashiCorp Vault
Software Vault
Native
DuoKey SD-HSM
Software-Defined HSM
MPC Cluster
Google Cloud KMS
Cloud KMS
Multi-Region
Fortanix SDKMS
Confidential Computing
Intel SGX
Atos TrustWay HSM
Hardware HSM
ANSSI Qualified
Crypto4A QxHSM
PQC-Ready HSM
Quantum-Safe
OpenBao
Software Vault
Vault-Compatible
HSM-Protected Keys
▼

HSM-Protected Secrets Management

Root keys never leave the HSM — auto-unseal, seal wrapping, and entropy augmentation all hardware-backed

Vault Enterprise+ DuoKey PKCS#11+ HSM Backend= Zero Trust Secrets
Vendor Independence
Mix and match backends — no HSM vendor lock-in
Auto-Unseal < 5s
Automated HSM-backed unsealing, no operator needed
FIPS 140-2 Level 3
Hardware-enforced key protection and lifecycle
Zero Downtime
HA failover with automatic backend selection

What is HashiCorp Vault?​

HashiCorp Vault is a secrets management system that allows you to securely store, manage, and grant access to secrets such as API tokens, passwords, and private keys.

The Enterprise edition offers additional advanced security and disaster recovery features:

Root Key Wrapping

Protect Vault's master key with a DuoKey Cockpit-managed AES-256 key

Automatic Unsealing

Unseal Vault automatically using a DuoKey Cockpit-managed key

Seal Wrapping

Additional encryption layer for sensitive secrets (a Vault Enterprise feature unlocked by any auto-unseal method, including DuoKey's)

Entropy Augmentation

Random number generation via the DuoKey Cockpit PKCS#11 endpoint

DuoKey Cockpit PKCS#11 Provider​

DuoKey Cockpit serves as a universal PKCS#11 provider, offering seamless integration with multiple vault and HSM backends. This unique architecture provides unparalleled flexibility in choosing and managing your key storage infrastructure.

Supported Vault Backends​

BackendTypeKey Features
DuoKey MPCMulti-Party ComputationDistributed key management, no single point of failure, FIPS-approved algorithms
Securosys CloudHSMCloud HSMSwiss-based, FIPS 140-2 Level 3 (Securosys certification), European data residency
HashiCorp VaultSoftware VaultNative integration, dynamic secrets, policy-based access
Azure Key VaultCloud KMSAzure AD auth, managed HSM, global availability
AWS KMSCloud KMSIAM integration, CloudHSM support, multi-region
Google Cloud KMSCloud KMSService-account auth, Cloud HSM, multi-region key rings
Utimaco HSMHardware HSMOn-premise, EAL5+ certified, high-performance
DuoKey SD-HSMSoftware-Defined HSMMPC-based cluster, no dedicated hardware, FIPS-approved algorithms
Fortanix SDKMSConfidential ComputingIntel SGX-backed, REST API, unified key management
Atos TrustWay HSMHardware HSMPKCS#11, ANSSI qualified, sovereign deployments
Crypto4A QxHSMPQC-Ready HSMPost-quantum algorithms, PKCS#11, hardware root of trust
OpenBaoSoftware VaultOpen-source Vault-compatible, Transit engine, token auth
Any vault backend

The wrapping key is an Active AES-256 key in any Cockpit-managed vault — the same DuoKey PKCS#11 provider used for this auto-unseal integration also backs Oracle TDE and Disk Encryption, and is not tied to one specific backend. Which backend is right for you (Software Vault, an HSM, or an MPC vault) is a question of your own key-custody requirements, not a limitation of this integration.

Key Features​

Enhanced Security

Cockpit-protected root keys, complete audit trail, regulatory compliance

Operational Excellence

Automatic unsealing, high availability, disaster recovery, zero downtime failover

Flexibility

PKCS#11 standard interface, hybrid deployment, API-first approach

Advanced Capabilities

Entropy augmentation, seal wrapping, key rotation

Use Cases​

Enterprise Secrets

Cockpit-managed encryption and automatic unsealing for secrets management

Multi-Cloud Strategy

Consistent key protection across AWS, Azure, GCP via unified interface

Financial Services

Meet PCI DSS, SOX requirements with centrally-managed key storage

Healthcare

HIPAA compliance with Cockpit-encrypted secrets and audit trails

Zero Trust

Centrally-managed authentication, encryption, and secrets distribution

Hybrid Cloud

Consistent secrets management across on-premise and cloud

Architecture Benefits​

Unified Management

Single PKCS#11 interface for all vault backends with centralized policy management

Vendor Independence

No lock-in to specific HSM vendor - mix and match backends as needed

Cost Optimization

Choose cost-effective backends per use case, leverage existing HSM investments

Community vs. Enterprise Comparison​

FeatureCommunity EditionEnterprise Edition
HSM IntegrationNot AvailablePKCS#11 Support
Auto-UnsealManual OnlyHSM-backed
Seal WrappingNot AvailableAvailable
Entropy AugmentationNot AvailableAvailable
Multi-AuthorizationLimitedFull Support
Root Key ProtectionSoftware OnlyHSM-backed
Tip

HashiCorp Vault Enterprise with DuoKey Cockpit integration provides a strong level of security for your secrets management infrastructure. Contact us to learn more about Enterprise licensing.

System Requirements​

Prerequisites

  • HashiCorp Vault Enterprise (any recent version)
  • PKCS#11 support enabled
  • Linux or Windows server environment
  • DuoKey Cockpit access (cloud or on-premise)
  • PKCS#11 provider library installed
  • Network connectivity to selected vault backend

Operating System Support​

PlatformVersions
LinuxRHEL/CentOS 7+, Ubuntu 18.04+, Debian 10+
WindowsWindows Server 2016+, Windows 10/11
ContainerDocker, Kubernetes support

Performance Characteristics​

MetricValue
Unsealing< 5 seconds
Seal Operations< 100ms
EntropyUp to 1MB/s random data
Cockpit Uptime SLA99.99% (target)
FailoverAutomatic (< 30 seconds)
Indicative targets

The figures above are indicative design targets, not independently benchmarked guarantees. Actual performance and availability depend on your deployment, backend and network.

Security Considerations​

Getting Started​

Important

Our integration specialists are available to help you design and implement the optimal HashiCorp Vault architecture for your organization.