Aller au contenu principal
encrypted dataAzure Managed HSMExternal Key Manager (EKM) protocolwrap / unwrapkey controlDuoKey Cockpityour key-encryption keyvault APIVault / HSMkey never exportedRevoke the key → instant lockout
Azure Managed HSM keeps the data; DuoKey keeps the key. You stay in control — revoke the key and the data goes dark, everywhere.
S'applique à :
Azure Managed HSMAzure SQL Transparent Data EncryptionCustomer-Managed Keys (CMK)External Key Manager (EKM)

What is Azure EKM?​

Azure's External Key Manager (EKM) protocol lets Azure Managed HSM delegate the wrap and unwrap of a Data Encryption Key (DEK) to a key manager you run, instead of storing the Key Encryption Key (KEK) inside Azure. Azure services configured with a Customer-Managed Key on top of Managed HSM — such as Azure SQL Database Transparent Data Encryption (TDE) or column-level encryption — call the EKM endpoint every time they need to protect or recover a DEK.

DuoKey Cockpit implements this protocol (API version 0.1-preview) as a built-in app: DuoKey acts as the EKM proxy, and the KEK never leaves your DuoKey vault.

Azure EKM request path
Azure SQL TDECustomer-Managed Key on Managed HSM
Azure Storage / other CMK workloadColumn-level encryption and similar
EKM protocol (0.1-preview) over mutual TLS
DuoKey Cockpit endpointUnguessable slug — /azureekm/{slug}mTLS-terminated: client CA validation, optional Subject CN pin
wrap / unwrap
Tenant vaultHolds the KEK (AES-256 or RSA-2048/4096)RSA private key never leaves it, even during wrap/unwrap

Azure calls the mTLS-terminated Cockpit endpoint for every wrap/unwrap; the KEK itself never leaves your tenant vault.

Wrap / Unwrap

Azure sends the DEK to be wrapped or unwrapped with your KEK — the KEK itself is never exposed to Azure

Mutual TLS

Every request is authenticated with a client certificate that must chain to a CA you configure

Algorithm Choice

AES Key Wrap (with or without padding) for AES-256 keys, or RSA-OAEP-256 for RSA keys

Self-Test & Health

Built-in wrap/unwrap round-trip test and a structured health check for the endpoint

How it fits the Cockpit Apps model​

Like DuoKey's other integrations, the Azure EKM proxy is an App deployed from the Cockpit Apps catalog — there is nothing to install separately. You deploy an EKM endpoint from the same interface you use to manage your other apps and keys, and the endpoint is bound to a single vault and key you select during deployment.

Supported algorithms​

AlgorithmKey typeDescription
A256KWAES-256AES Key Wrap (RFC 3394)
A256KWPAES-256AES Key Wrap with Padding (RFC 5649) — for arbitrary-length plaintext
RSA-OAEP-256RSA-2048 / RSA-4096RSA-OAEP with SHA-256
Where the cryptography happens

For AES algorithms, the wrap/unwrap is performed using the raw KEK fetched from your vault. For RSA-OAEP-256, the operation is delegated to the vault adapter instead, so an HSM-backed RSA private key never leaves the vault.

How it works​

1

Azure needs to protect or recover a DEK

Azure Managed HSM (or an Azure service configured with a Managed HSM Customer-Managed Key, such as Azure SQL TDE) needs to wrap a new DEK, or unwrap a previously wrapped one.

2

Azure calls your EKM proxy over mTLS

Azure presents a client certificate on every request. If mutual TLS is required for the endpoint (the default), DuoKey verifies the certificate chains to the client CA you configured and, if you pinned an expected Subject CN, that the certificate's CN matches it.

3

DuoKey resolves the endpoint's key

The unguessable endpoint path (its slug) resolves to the vault and key you selected when you deployed the endpoint — the Key Encryption Key.

4

Wrap or unwrap runs against the KEK

For A256KW/A256KWP the operation runs against the KEK's raw key material fetched from the vault; for RSA-OAEP-256 it is delegated to the vault so the private key never leaves it.

5

Result returned to Azure

The wrapped (or unwrapped) key bytes are returned to Azure over the same mTLS connection. If audit logging is enabled on the key, the operation is recorded in DuoKey's audit trail.

Endpoints created on deployment​

Deploying an Azure EKM app creates one endpoint, identified by an auto-generated slug, under /azureekm/<slug>:

OperationPathPurpose
Proxy infoPOST /azureekm/{slug}/infoReturns proxy identification, used by Azure to discover the endpoint
Key metadataPOST /azureekm/{slug}/{key_name}/metadataReturns key type, size and supported operations (and, for RSA keys, the public modulus/exponent)
WrapPOST /azureekm/{slug}/{key_name}/wrapkeyEncrypts a DEK with the KEK
UnwrapPOST /azureekm/{slug}/{key_name}/unwrapkeyDecrypts a previously wrapped DEK
HealthGET /azureekm/{slug}/healthSimple health check for monitoring
No JWT on the protocol endpoints

These endpoints authenticate Azure with mutual TLS and the unguessable slug — not a user session or JWT. The slug is generated when you deploy the endpoint and should be treated as a credential.

Key features​

Mutual TLS

Client CA validation with optional Subject CN pinning to a specific Managed HSM identity

AES & RSA algorithms

A256KW, A256KWP, and RSA-OAEP-256 — restrict which are allowed per endpoint

Vault-backed KEK

The key never leaves your DuoKey vault; RSA private keys never leave it even during wrap/unwrap

Self-test

One-click wrap/unwrap round trip — against the real key for an AES-256 KEK, or a synthetic plumbing check otherwise; the endpoint health check exercises the real key for RSA too

Structured health check

Verifies deployment, key availability, wrap/unwrap, and mTLS configuration in one call

Audit logging

Wrap and unwrap operations are recorded when audit logging is enabled on the key

Use cases​

Azure SQL TDE

Protect SQL Database Transparent Data Encryption keys with a KEK you control, outside Azure Managed HSM.

Column-level encryption

Use the same externally-held KEK for Always Encrypted / column-level encryption scenarios built on Managed HSM CMK.

Key sovereignty

Keep the key-encryption key under your own control while Azure continues to manage the encrypted data.

Instant revocation

Disable the endpoint or the key in DuoKey and Azure immediately loses the ability to wrap or unwrap.

Prerequisites​

Prérequis

  • An Azure Managed HSM (or Azure service backed by one) configured for Customer-Managed Keys / External Key Manager
  • The client CA certificate that issues Azure's client certificate for the EKM connection
  • A DuoKey vault with an AES-256 key (for A256KW/A256KWP) or an RSA-2048/4096 key (for RSA-OAEP-256)
  • DuoKey Cockpit admin access with permission to manage Apps

Getting Started​

Vendor Documentation​