Skip to main content

overview

Applications& internal servicesDuoKey Cockpitunified control & auditTransit key backendOpenBaoTransit engine (Vault-compatible)
DuoKey drives OpenBao as a Transit key backend, so keys and secrets are managed from one console with a single audit trail.
Applies to:
OpenBao (Community Fork)PKCS#11 Auto-UnsealDuoKey Cockpit-managed vaultLinux / Container / Cloud

DuoKey provides seamless PKCS#11 integration with OpenBao, the community-driven fork of HashiCorp Vault, enabling you to auto-unseal your vault using an AES-256 key managed in your DuoKey Cockpit.

OpenBao Auto-Unseal with DuoKey MPC

Zero-trust secrets management with threshold cryptography — no single point of failure

Traditional Shamir

Manual Process
Multiple operators required
Manual unseal on every restart
Availability bottleneck
Human error risk
→

DuoKey MPC Auto-Unseal

Zero Trust
Automatic, < 5 seconds
No single point of failure
High availability
FIPS 140-2 Level 3
Auto-Unseal Runtime Flow
▼

OpenBao Server

Open Source Secrets Management
Seal Stanza
PKCS#11 auto-unseal config
Secret Engines
KV, Transit, PKI, SSH
Auth Methods
LDAP, OIDC, AppRole, K8s
Audit Devices
File, Syslog, Socket
MPL 2.0 LicenseCommunity GovernedNo Vendor Lock-In
PKCS#11 API
▼

PKCS#11 Provider

Routes unseal requests to DuoKey MPC via standard cryptographic interface

PKCS#11 Interface
Standard HSM API
Request Router
Backend selection
Policy Engine
Access control
Audit Trail
Full operation log
Threshold Crypto Request
▼
Node A
Switzerland
Key Share A
Node B
EU Region
Key Share B
Node C
Customer DC
Key Share C

Unseal key computed via Secure Multi-Party Computation — the full key never exists in any single location

Unseal Key Returned
▼

OpenBao Auto-Unsealed

Vault ready in < 5 seconds — zero manual intervention, zero single point of failure

OpenBao+ PKCS#11+ DuoKey MPC= Zero Trust Secrets
1
OpenBao Starts
Initialization
2
Request Unseal
Auto-unseal trigger
3
PKCS#11 Call
Interface invoked
4
Cockpit Routes
Backend selected
5
MPC Computes
Threshold crypto
6
Key Returned
Sealed response
7
Vault Unsealed
Ready for ops
Truly Open Source
MPL 2.0 forever, community-governed, no vendor lock-in
Auto-Unseal < 5s
No operator needed, fully automated on every restart
Zero Trust MPC
Key shares across nodes — full key never exists anywhere
Cost Effective
No enterprise licensing, open source with MPC security

What is OpenBao?​

OpenBao is an open-source, community-driven fork of HashiCorp Vault that emerged to ensure the project remains truly open source and community-governed. OpenBao is "an identity-based secrets and encryption management system" that stores secrets securely, provides identity-based access, and generates dynamic secrets on demand.

The Unsealing Challenge​

When OpenBao starts, the vault needs to be "unsealed" before it can be used. Traditionally, OpenBao uses Shamir's secret sharing, which requires multiple human operators to manually unseal - causing availability issues and operational overhead.

ApproachLimitation
Traditional ShamirRequires multiple human operators to manually unseal
Traditional ShamirCauses availability issues during unplanned restarts
Traditional ShamirOperational overhead and potential delays
Traditional ShamirHuman error risks

Modern Solution: Auto-Unseal with DuoKey​

Automatic Unsealing

No manual intervention required when OpenBao starts

Centralized Key Control

The wrapping key's lifecycle is managed in DuoKey Cockpit — deactivating or revoking it immediately blocks unsealing

Authenticated Encryption

AES-256-GCM wrap/unwrap of OpenBao's root key, performed inside the DuoKey Cockpit

Fast Unsealing

Sub-second unsealing latency in typical deployments

Key Features​

Automatic Unsealing

Zero manual key entry, eliminates human operator dependencies, ensures high availability

Enhanced Security

AES-256-GCM key wrap with Cockpit-enforced key lifecycle controls (Active / Deactivated / Compromised)

Operational Excellence

Zero downtime unsealing, seamless failover, comprehensive audit logging

Flexibility

PKCS#11 library or native OpenBao KMS plugin, works with existing deployments, hybrid and multi-cloud support

Benefits​

Use Cases​

Enterprise Secrets

Auto-unseal across infrastructure without manual intervention

Cloud-Native Apps

Deploy in Kubernetes with automatic unsealing for seamless scaling

Zero Trust

OpenBao never holds the unsealing key — only DuoKey Cockpit does

Financial Services

Meet regulatory requirements with centrally-managed, auditable key custody

Multi-Cloud

Consistent deployment across AWS, Azure, GCP, and on-premise

Healthcare

HIPAA compliance with centrally-managed vault unsealing

Community vs Enterprise Comparison​

FeatureOpenBao (Community)OpenBao + DuoKey
Open SourceFully Open SourceFully Open Source
Auto-UnsealSupported (PKCS#11 or KMS plugin)Backed by a Cockpit-managed AES-256 key
Key CustodyDepends on configured sealCentralized in a DuoKey Cockpit-managed vault (Software Vault, HSM, or MPC)
Key Lifecycle ControlNot built-inActive / Deactivated / Compromised states gate unsealing
Geographic DistributionNot NativeDepends on Cockpit deployment
AuditabilityLimitedCentralized audit trail in DuoKey Cockpit

How It Works​

Create the Key

Create (or select) an Active AES-256 key in any DuoKey Cockpit-managed vault

Deploy the Auto-Unseal App

Deploy an OpenBao auto-unseal app in DuoKey Cockpit, linked to that key

Install the Provider

Install the DuoKey PKCS#11 library (or the native OpenBao KMS plugin) on the OpenBao server

OpenBao Configuration

Configure the OpenBao seal stanza generated by DuoKey Cockpit

Initialization

Initialize OpenBao with the auto-unseal configuration

Automatic Unsealing

OpenBao automatically unseals using the DuoKey-managed key on startup

System Requirements​

Prerequisites

  • OpenBao latest version with PKCS#11 support enabled (or the DuoKey native KMS plugin for OpenBao 2.7+)
  • DuoKey Cockpit account with an Active AES-256 key in any Cockpit-managed vault
  • PKCS#11 provider library (or DuoKey KMS plugin) installed
  • Network connectivity to the DuoKey Cockpit (HTTPS/443)
  • Linux server environment (recommended)

Operating System Support​

PlatformVersions
LinuxRHEL/CentOS 7+, Ubuntu 18.04+, Debian 10+
ContainerDocker, Kubernetes support
CloudAWS, Azure, GCP compatible

Performance Characteristics​

MetricValue
Unsealing Time< 5 seconds
Key Operation LatencySub-100ms
Cockpit Uptime SLA99.99% (target)
FailoverAutomatic (< 30 seconds)
ScalabilitySupports thousands of concurrent vaults
Indicative targets

These figures are indicative design targets, not independently benchmarked guarantees. Actual results depend on your deployment, backend and network.

Why Choose OpenBao?​

Truly Open Source

No vendor lock-in, MPL 2.0 forever, community governance

Zero Trust by Design

The wrapping key is centrally managed and access-controlled in DuoKey Cockpit, never held by OpenBao itself

Cost Effective

No enterprise licensing fees with complete infrastructure ownership

Getting Started​

Ready to configure OpenBao auto-unseal with DuoKey? Follow our step-by-step guide:

  • Setup & Configuration — Complete instructions including environment variables, the AES-GCM seal stanza, and troubleshooting
Tip

Our integration specialists are available to help you design and implement OpenBao auto-unseal with DuoKey for your organization.