Skip to main content

Primus HSM - Key Invalidation

Key Invalidation is a Primus HSM feature which mitigates accidental deletion of keys via the API.

When enabled, API requests to delete a key will place the key into a "trash bin". The key will appear deleted to the API and is no longer visible or usable.

Invalidated keys remain in the "trash bin" until deleted or reactivated. The SO or PSO must manually remove the invalidated keys, or in case of accidental deletion, reactivate the individual key(s). Once invalidated keys are removed by the SO/PSO, they are permanently deleted.

Invalidated keys are still present on the Partition, meaning that:

  1. Creating a new key with the same label will fail.
  2. Invalidated keys count towards the storage quota of the Partition. Regularly remove or reactivate the invalidated keys to ensure your Partition size can accommodate enough keys.

Key Invalidation can be activated in the device-wide or the per-Partition Security Configuration.

For more details and instructions for SOs/PSOs, see Section 5.6.4 "Key Invalidation" of the Primus HSM User Guide.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?