overview
DuoKey for HashiCorp Vault
Enterprise-grade PKCS#11 integration with HashiCorp Vault for auto-unseal secrets management
DuoKey provides seamless PKCS#11 integration with HashiCorp Vault Enterprise, enabling you to auto-unseal your Vault's root key using an AES-256 key managed in your DuoKey Cockpit.
HashiCorp Vault + DuoKey PKCS#11 Architecture
Enterprise-grade HSM-backed secrets management with multi-backend flexibility
HashiCorp Vault Enterprise
Secrets ManagementUniversal PKCS#11 Provider
Seamless integration with multiple vault and HSM backends
HSM-Protected Secrets Management
Root keys never leave the HSM — auto-unseal, seal wrapping, and entropy augmentation all hardware-backed
What is HashiCorp Vault?
HashiCorp Vault is a secrets management system that allows you to securely store, manage, and grant access to secrets such as API tokens, passwords, and private keys.
The Enterprise edition offers additional advanced security and disaster recovery features:
Root Key Wrapping
Protect Vault's master key with a DuoKey Cockpit-managed AES-256 key
Automatic Unsealing
Unseal Vault automatically using a DuoKey Cockpit-managed key
Seal Wrapping
Additional encryption layer for sensitive secrets (a Vault Enterprise feature unlocked by any auto-unseal method, including DuoKey's)
Entropy Augmentation
Random number generation via the DuoKey Cockpit PKCS#11 endpoint
DuoKey Cockpit PKCS#11 Provider
DuoKey Cockpit serves as a universal PKCS#11 provider, offering seamless integration with multiple vault and HSM backends. This unique architecture provides unparalleled flexibility in choosing and managing your key storage infrastructure.
Supported Vault Backends
| Backend | Type | Key Features |
|---|---|---|
| DuoKey MPC | Multi-Party Computation | Distributed key management, no single point of failure, FIPS-approved algorithms |
| Securosys CloudHSM | Cloud HSM | Swiss-based, FIPS 140-2 Level 3 (Securosys certification), European data residency |
| HashiCorp Vault | Software Vault | Native integration, dynamic secrets, policy-based access |
| Azure Key Vault | Cloud KMS | Azure AD auth, managed HSM, global availability |
| AWS KMS | Cloud KMS | IAM integration, CloudHSM support, multi-region |
| Google Cloud KMS | Cloud KMS | Service-account auth, Cloud HSM, multi-region key rings |
| Utimaco HSM | Hardware HSM | On-premise, EAL5+ certified, high-performance |
| DuoKey SD-HSM | Software-Defined HSM | MPC-based cluster, no dedicated hardware, FIPS-approved algorithms |
| Fortanix SDKMS | Confidential Computing | Intel SGX-backed, REST API, unified key management |
| Atos TrustWay HSM | Hardware HSM | PKCS#11, ANSSI qualified, sovereign deployments |
| Crypto4A QxHSM | PQC-Ready HSM | Post-quantum algorithms, PKCS#11, hardware root of trust |
| OpenBao | Software Vault | Open-source Vault-compatible, Transit engine, token auth |
The wrapping key is an Active AES-256 key in any Cockpit-managed vault — the same DuoKey PKCS#11 provider used for this auto-unseal integration also backs Oracle TDE and Disk Encryption, and is not tied to one specific backend. Which backend is right for you (Software Vault, an HSM, or an MPC vault) is a question of your own key-custody requirements, not a limitation of this integration.
Key Features
Enhanced Security
Cockpit-protected root keys, complete audit trail, regulatory compliance
Operational Excellence
Automatic unsealing, high availability, disaster recovery, zero downtime failover
Flexibility
PKCS#11 standard interface, hybrid deployment, API-first approach
Advanced Capabilities
Entropy augmentation, seal wrapping, key rotation
Use Cases
Enterprise Secrets
Cockpit-managed encryption and automatic unsealing for secrets management
Multi-Cloud Strategy
Consistent key protection across AWS, Azure, GCP via unified interface
Financial Services
Meet PCI DSS, SOX requirements with centrally-managed key storage
Healthcare
HIPAA compliance with Cockpit-encrypted secrets and audit trails
Zero Trust
Centrally-managed authentication, encryption, and secrets distribution
Hybrid Cloud
Consistent secrets management across on-premise and cloud
Architecture Benefits
Unified Management
Single PKCS#11 interface for all vault backends with centralized policy management
Vendor Independence
No lock-in to specific HSM vendor - mix and match backends as needed
Cost Optimization
Choose cost-effective backends per use case, leverage existing HSM investments
Community vs. Enterprise Comparison
| Feature | Community Edition | Enterprise Edition |
|---|---|---|
| HSM Integration | Not Available | PKCS#11 Support |
| Auto-Unseal | Manual Only | HSM-backed |
| Seal Wrapping | Not Available | Available |
| Entropy Augmentation | Not Available | Available |
| Multi-Authorization | Limited | Full Support |
| Root Key Protection | Software Only | HSM-backed |
HashiCorp Vault Enterprise with DuoKey Cockpit integration provides a strong level of security for your secrets management infrastructure. Contact us to learn more about Enterprise licensing.
System Requirements
Prerequisites
- HashiCorp Vault Enterprise (any recent version)
- PKCS#11 support enabled
- Linux or Windows server environment
- DuoKey Cockpit access (cloud or on-premise)
- PKCS#11 provider library installed
- Network connectivity to selected vault backend
Operating System Support
| Platform | Versions |
|---|---|
| Linux | RHEL/CentOS 7+, Ubuntu 18.04+, Debian 10+ |
| Windows | Windows Server 2016+, Windows 10/11 |
| Container | Docker, Kubernetes support |
Performance Characteristics
| Metric | Value |
|---|---|
| Unsealing | < 5 seconds |
| Seal Operations | < 100ms |
| Entropy | Up to 1MB/s random data |
| Cockpit Uptime SLA | 99.99% (target) |
| Failover | Automatic (< 30 seconds) |
The figures above are indicative design targets, not independently benchmarked guarantees. Actual performance and availability depend on your deployment, backend and network.
Security Considerations
Getting Started
Our integration specialists are available to help you design and implement the optimal HashiCorp Vault architecture for your organization.