About this guide
About Cryptographic Security Platform
About CSP Vault
Major Components
Entrust Hardened OS
CSP Vault Clusters
About Entrust Policy Agent
Encryption Key Sizes and Algorithms
Secure File Migration
Administrative Model
Administrative Interfaces
CSP Vault Management webGUI Overview
CSP Vault System Console Overview
Entrust Policy Agent GUI Overview
Release notes
Requirements
System resources
Network requirements
Supported platforms
Browser Requirements
Installing CSP Vault
Installation Overview
CSP Vault OVA Installation
OVA installation overview
Installing CSP Vault from an OVA Template
Configuring the First CSP Vault Node (OVA Install)
Adding a New CSP Vault Node to an Existing Cluster (OVA Install)
CSP Vault ISO Installation for Hypervisor
ISO Installation Overview
Installing the First CSP Vault Node from an ISO Image
Installing an Additional CSP Vault Cluster Node from an ISO Image
CSP Vault ISO Installation for Bare Metal Server
ISO Installation Overview for Bare Metal Server
Prerequisites and Requirements for Installing CSP Vault on a Bare Metal Server
Installing the First CSP Vault Node on a Bare Metal Server from an ISO
Installing an Additional CSP Vault Node on a Bare Metal Server from an ISO
CSP Vault in Amazon Web Services
AWS Deployment Overview
Deploying the First CSP Vault Node in AWS
Associating an Elastic IP Address with the CSP Vault Instance
Configuring the First CSP Vault Node in AWS
Deploying Additional CSP Vault Nodes in AWS
Configuring Additional CSP Vault Nodes in AWS
CSP Vault in Google Cloud Platform
GCP Deployment Overview
Deploying the First CSP Vault Node in GCP
Configuring Firewall Rules for the CSP Vault Instance
Configuring the First GCP Node
Configuring Additional GCP Nodes
CSP Vault in Microsoft Azure
Azure Deployment Overview
Recommendations
Deploying a CSP Vault Node in Azure
Configuring the First CSP Vault Node in Azure
Configuring Additional CSP Vault Nodes in Azure
Initializing the CSP Vault Management webGUI
Upgrading CSP Vault
CSP Vault Upgrade Paths
CSP Vault Upgrade Requirements
Upgrading CSP Vault to 10.6.1
Installing Policy Agent
Preparing to Install the Policy Agent
Linux Policy Agent Installation
Linux Policy Agent Installation Overview
Linux Installation Prerequisites
Installing the Policy Agent on Linux
Authenticating a New VM
Windows Policy Agent Installation
Windows Installation Prerequisites
Windows Boot Drive Installation Prerequisites
Installing Interactively on Windows
Installing Silently on Windows
Registering the Policy Agent Using the Entrust Policy Agent GUI
Registering the Policy Agent from the Windows Command Line
Uninstalling Silently on Windows
Upgrading Policy Agent
Policy Agent Upgrade Requirements
Upgrading Policy Agent with the webGUI
Upgrading the Policy Agent on Linux
Upgrading the Policy Agent on Windows
CSP Vault Appliance Management
CSP Vault System Configuration
Enabling an HTTP Proxy Server in CSP Vault
Network Interface Configuration Options
Multi-NIC Node Configuration
Configuring Multiple NICs on an Existing CSP Vault
Removing a NIC from the Configuration
Configuring DNS Settings
Configuring NTP Settings
Configuring Static Routes
Configuring TLS
Uploading an OIDC CA Certificate
Setting Email Server Preferences
Setting CSP Vault Console Settings
Syslog Server Settings
Configuring Syslog Server Settings
Resetting Syslog Server Settings
CSP Vault Certificates
About CSP Vault Certificates
Viewing the Expiration Date for the Current CSP Vault SSL Certificate
Creating a Certificate Signing Request
Using Self-Signed Certificates for All Nodes in a Cluster
Generating and Installing a Custom Self-Signed Certificate
Installing External Certificates for Internal and External Webservers
CSP Vault Certificate Expiration Notification
Installing a New Self-Signed Certificate for a Node
Downloading a CSP Vault CA Certificate
Troubleshooting Certificate Issues
Manually Updating the CA Certificate on a Linux Root Drive Encrypted VM
Manually Updating the CA Certificate on a Data Encrypted VM
Manually Updating the CA Certificate on a Windows Boot Drive Encrypted VM
Admin Keys
Downloading Your Admin Key Part
Generating the Admin Key
Verifying the Admin Key
KMIP Server Configuration
KEKs with KMIP
Configuring a New KMIP Server
Creating a Certificate Signing Request for KMIP Server
Installing a Custom Certificate
Hardware Security Modules with CSP Vault
Adding a CSP Vault Node to a Cluster using an nShield HSM client
Configuring CSP Vault as an HSM Client using an nShield HSM
Adding HSM Root-of-Trust to nShield Server
Running nShield HSM Info Commands in the webGUI
Configuring an nShield HSM for High Availability
Replacing an nShield HSM on a CSP Vault Cluster
Configuring Allowed Smart Cards for an nShield HSM
KeySafe5 Agent Requirements
Enabling the KeySafe5 Agent
Configuring CSP Vault as a Luna Cloud HSM Client
Configuring CSP Vault as a Luna HSM Client with a Single Cluster Certificate
Configuring CSP Vault as a Luna HSM Client with Individual Node Certificates
Configuring a Luna HSM HA Group
Adding a CSP Vault Node to an Existing Luna HSM Configuration
Adding a New Luna HSM to an Existing Luna HSM Configuration
Adding a Luna Cloud HSM to an Existing Luna HSM Configuration
Changing the Luna Client Certificate Mode
Locating the HSM Server Admin Key
Resetting the HSM Server Configuration
SNMP Traps in Cryptographic Security Platform Vault
Configuring Group-Level SNMP Traps
Configuring SNMP Agent Users for Polling
Configuring System-Level SNMP Traps
Downloading the SNMP MIB File
SNMP MIB File
Setting CSP Vault Management webGUI Alert Settings
Using the Entrust CSP Vault System Console
CSP Vault Authentication and User Accounts
Authentication for CSP Vault User Accounts
Configuring Local Authentication Settings
Specifying an LDAP/AD Authentication Server
Specifying an OpenLDAP Authentication Server
Configuring OIDC with Active Directory for CSP Vault
Configuring OIDC for Cryptographic Security Platform Vault
Configuring an OpenID Connect Provider
Setting the CSP Vault Management webGUI Session Timeout
Setting the Default Account Expiration
Creating a New CSP Vault-Managed User Account
Setting webGUI User Preferences
Changing Your CSP Vault User Account Settings
Setting the secroot Account Expiration
Resetting the secroot Account Password
About Two-Factor Authentication
Enabling Two-Factor Authentication
Managing Two-Factor Authentication
Changing CSP Vault Account Details as a Security Administrator
Re-enabling a CSP Vault-Managed User Account
CSP Vault Cluster Maintenance
CSP Vault Nodes and Clusters
Viewing the Cluster Status
Setting Cluster Options
Switching a Master Node
Choosing the Node Failover Order
Startup Authentication
Enabling Startup Authentication
Disabling Startup Authentication
CSP Vault Backup and Restore
Backing Up CSP Vault Through the webGUI
Backup and Restore Using the API
Backup Image Status
Create Object Store Backup Image
Creating a Backup User
Download Object Store Backup Image
Restore Backup Image
Restoring CSP Vault Through the webGUI
Joining or Re-joining a Cryptographic Security Platform Vault Cluster
Joining a CSP Vault Cluster
Re-Joining a CSP Vault Cluster
Upload Backup Image
Removing a CSP Vault Node from a Cluster
Changing the IP Address for a Node
Rebooting a CSP Vault Node
Decommissioning a CSP Vault Node
Enabling or Disabling the Support Login
Accessing CSP Vault Backup Files
CSP Vault System Maintenance and Troubleshooting
CSP Vault Activity Tracking
Managing Alerts
Viewing the Audit Log
Configuring Audit Log Settings
Exporting the Audit Log
Moving a CSP Vault Node to a New Server in a Multi-Node Environment
Moving a CSP Vault Node to a New Server in a Single Node Environment
Increasing CSP Vault Storage in a VM
VM Handlers for Attach/Detach in Linux
VM Handlers for Attach/Detach in Windows
Upgrading to a New Hardware Signature Format
Troubleshooting Network Issues
Cleaning Up Stale Tasks
Support Access and Log Files
Using the Restricted Shell
Creating a Support Bundle with the webGUI
Creating a Support Bundle from the CSP Vault System Console
Disabling CSP Vault Support Logins
Policy Agent Support Logs
Backing Up the Policy Agent
Uninstalling the Policy Agent on Linux
Uninstalling the Policy Agent on Windows
KMIP Errors and Troubleshooting
Revert to Previous CSP Vault Version
Delete CSP Vault Snapshots
Troubleshooting CSP Platform Vault from the Bootloader
Recovering Access to CSP Vault
CSP Vault Management webGUI Page Reference
Alerts Page
Audit Log Page
Cluster Page
HSM Server Settings Page
Proxy Settings
Users Page
Settings Page
SNMP Settings Page
License Page
Syslog Server Settings Page
System Decommission Page
System Upgrade Page
Vault Management
Vault Management Overview
Managing Vaults
Creating a Vault
Rescuing a Vault
Editing a Vault
Viewing Vault Details
Renaming a Vault
Deleting a Vault
Connecting CSP Vault and CSP Compliance Manager
Initializing a Data Source Connection in CSP Compliance Manager
Connecting a CSP Vault to CSP Compliance Manager
Disconnecting a CSP Vault from CSP Compliance Manager
CSP Vault Audit Messages 10.6.1
CSP Vault Audit Messages
CSP Vault for Cryptographic APIs Audit Messages
CSP Vault for KMIP Audit Messages
CSP Vault for Secrets Audit Messages
Differences in CSP Vault Audit Messages
Customer license
Programmer's Reference Guide
hicli Scripting Guide
Introduction
Installing and Configuring hicli
hicli Command Categories
Selecting a CSP Vault Node
Domain Management
Cloud Admin Group Management
User Management
Examples: Logging In and Viewing Users
Examples: Creating and Modifying Users
Examples: Removing Users
Cloud VM Set Management
Examples: Creating and Changing Cloud VM Sets
Examples: Cloud VM Sets with the KEK Feature
Examples: Cloud VM Set Certificates
Examples: KeyIDs
VM Management
KMIP Server Management
KMIP Server Object Management
AWS S3 Bucket Management
Alert Management
Man Page Reference
hcl Man Page
htroot Man Page
hcs3 Man Page
CSP Vault with VSAN and VMware vSphere VM Encryption
CSP Vault with VSAN and VMware vSphere VM Encryption Overview
Configuring a KMIP Server for vSphere KMS
Adding a KMS Cluster in vSphere
Establishing a Trusted Connection with a vSphere-Generated CSR
Establishing a Trusted Connection with a CSP Vault-Generated CSR
Troubleshooting