Skip to main content

Primus CNG/KSP API Provider

This guide describes the installation and update of the Primus CNG/KSP Provider on Microsoft Windows Server or Client, to integrate Securosys Hardware Security Modules (HSMs), both cloud & on-premise.

The provider is delivered as a Windows Installer package (MSI) which can be distributed via AD group policy.

Screenshot showing CNG-based services

Securosys HSMs are built to securely generate and store true random cryptographic keys, providing central, certified secure storage. They also control and regulate access to the keys and the related crypto-graphic functionality.

Securosys HSMs meets or exceeds the best practice security requirements and is one step ahead of fulfilling your compliance demands by providing:

  • Hardware-based secure generation of true random cryptographic keys
  • Central and highly secure storage of cryptographic keys
  • Load balancing and fail-over by clustering the HSMs
  • Controlled and regulated access to the keys
  • Hardware acceleration of cryptographic operations such as encryption, authentication, and digital signatures, relieving the host server of processor-intensive computations
  • Scalable performance at manageable cost

All certificate issuance and validation processes occur within the protected confines of the HSM. Private keys are never accessible outside the HSM.

Securosys HSMs can easily be integrated into a Microsoft Windows system by installing the Primus CNG Provider. This enables all Windows servers and clients to generate and store their private keys and certificates securely in the HSMs, and perform all related cryptographic functionality, hardware accelerated on the Primus HSM.

The CNG/KSP Provider is delivered as an MSI package, which can be installed interactive via GUI, on the command line with additional parameters (e.g. to configure from file), via Active Directory Group Policy or other software distribution tools. CNG/KSP Provider supports installation of multiple instances (via configuration file only).

tip

Primus CNG/KSP Provider v1.60 and later supports post-quantum cryptography (PQC) algorithms. This requires a compatible version of Windows, Windows Server, .NET or AD CS.

What's Next

For a smooth start with the Primus CNG/KSP Provider:

  • Consult the quickstart guide for a quick onboarding.
  • For detailed instructions, read and follow the Installation guide.
  • Initiate the usage and hardening by reading and following the Tutorial section.
  • Delve into the Use-Cases section for application notes on different use cases.
Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?