overview
DuoKey for OpenBao
Auto-unseal OpenBao with a DuoKey-managed key for zero-trust secrets management
DuoKey provides seamless PKCS#11 integration with OpenBao, the community-driven fork of HashiCorp Vault, enabling you to auto-unseal your vault using an AES-256 key managed in your DuoKey Cockpit.
OpenBao Auto-Unseal with DuoKey MPC
Zero-trust secrets management with threshold cryptography — no single point of failure
Traditional Shamir
Manual ProcessDuoKey MPC Auto-Unseal
Zero TrustOpenBao Server
Open Source Secrets ManagementPKCS#11 Provider
Routes unseal requests to DuoKey MPC via standard cryptographic interface
Unseal key computed via Secure Multi-Party Computation — the full key never exists in any single location
OpenBao Auto-Unsealed
Vault ready in < 5 seconds — zero manual intervention, zero single point of failure
What is OpenBao?
OpenBao is an open-source, community-driven fork of HashiCorp Vault that emerged to ensure the project remains truly open source and community-governed. OpenBao is "an identity-based secrets and encryption management system" that stores secrets securely, provides identity-based access, and generates dynamic secrets on demand.
The Unsealing Challenge
When OpenBao starts, the vault needs to be "unsealed" before it can be used. Traditionally, OpenBao uses Shamir's secret sharing, which requires multiple human operators to manually unseal - causing availability issues and operational overhead.
| Approach | Limitation |
|---|---|
| Traditional Shamir | Requires multiple human operators to manually unseal |
| Traditional Shamir | Causes availability issues during unplanned restarts |
| Traditional Shamir | Operational overhead and potential delays |
| Traditional Shamir | Human error risks |
Modern Solution: Auto-Unseal with DuoKey
Automatic Unsealing
No manual intervention required when OpenBao starts
Centralized Key Control
The wrapping key's lifecycle is managed in DuoKey Cockpit — deactivating or revoking it immediately blocks unsealing
Authenticated Encryption
AES-256-GCM wrap/unwrap of OpenBao's root key, performed inside the DuoKey Cockpit
Fast Unsealing
Sub-second unsealing latency in typical deployments
Key Features
Automatic Unsealing
Zero manual key entry, eliminates human operator dependencies, ensures high availability
Enhanced Security
AES-256-GCM key wrap with Cockpit-enforced key lifecycle controls (Active / Deactivated / Compromised)
Operational Excellence
Zero downtime unsealing, seamless failover, comprehensive audit logging
Flexibility
PKCS#11 library or native OpenBao KMS plugin, works with existing deployments, hybrid and multi-cloud support
Benefits
Use Cases
Enterprise Secrets
Auto-unseal across infrastructure without manual intervention
Cloud-Native Apps
Deploy in Kubernetes with automatic unsealing for seamless scaling
Zero Trust
OpenBao never holds the unsealing key — only DuoKey Cockpit does
Financial Services
Meet regulatory requirements with centrally-managed, auditable key custody
Multi-Cloud
Consistent deployment across AWS, Azure, GCP, and on-premise
Healthcare
HIPAA compliance with centrally-managed vault unsealing
Community vs Enterprise Comparison
| Feature | OpenBao (Community) | OpenBao + DuoKey |
|---|---|---|
| Open Source | Fully Open Source | Fully Open Source |
| Auto-Unseal | Supported (PKCS#11 or KMS plugin) | Backed by a Cockpit-managed AES-256 key |
| Key Custody | Depends on configured seal | Centralized in a DuoKey Cockpit-managed vault (Software Vault, HSM, or MPC) |
| Key Lifecycle Control | Not built-in | Active / Deactivated / Compromised states gate unsealing |
| Geographic Distribution | Not Native | Depends on Cockpit deployment |
| Auditability | Limited | Centralized audit trail in DuoKey Cockpit |
How It Works
Create the Key
Deploy the Auto-Unseal App
Install the Provider
OpenBao Configuration
Initialization
Automatic Unsealing
System Requirements
Prerequisites
- OpenBao latest version with PKCS#11 support enabled (or the DuoKey native KMS plugin for OpenBao 2.7+)
- DuoKey Cockpit account with an Active AES-256 key in any Cockpit-managed vault
- PKCS#11 provider library (or DuoKey KMS plugin) installed
- Network connectivity to the DuoKey Cockpit (HTTPS/443)
- Linux server environment (recommended)
Operating System Support
| Platform | Versions |
|---|---|
| Linux | RHEL/CentOS 7+, Ubuntu 18.04+, Debian 10+ |
| Container | Docker, Kubernetes support |
| Cloud | AWS, Azure, GCP compatible |
Performance Characteristics
| Metric | Value |
|---|---|
| Unsealing Time | < 5 seconds |
| Key Operation Latency | Sub-100ms |
| Cockpit Uptime SLA | 99.99% (target) |
| Failover | Automatic (< 30 seconds) |
| Scalability | Supports thousands of concurrent vaults |
These figures are indicative design targets, not independently benchmarked guarantees. Actual results depend on your deployment, backend and network.
Why Choose OpenBao?
Truly Open Source
No vendor lock-in, MPL 2.0 forever, community governance
Zero Trust by Design
The wrapping key is centrally managed and access-controlled in DuoKey Cockpit, never held by OpenBao itself
Cost Effective
No enterprise licensing fees with complete infrastructure ownership
Getting Started
Ready to configure OpenBao auto-unseal with DuoKey? Follow our step-by-step guide:
- Setup & Configuration — Complete instructions including environment variables, the AES-GCM seal stanza, and troubleshooting
Our integration specialists are available to help you design and implement OpenBao auto-unseal with DuoKey for your organization.