Is there any usage of private key after AWS Cloud HSM cluster is initialized?

1

Hello, This question is related to Cloud HSM cluster initialization process and usage of the private key once cluster is initialized.

What is the usage of the private key which was used to the sign the cluster CSR ? Based on https://docs.aws.amazon.com/cloudhsm/latest/userguide/initialize-cluster.html#sign-csr, once we signed the CSR, we have to secure the private key to the secure storage (offline HSM). If you can demonstrate that you own the key, you can also demonstrate that you own the cluster and the data it contains.

Documentation says that this private key will not be used for Cloud HSM operations except only for specific purposes such as restoring from a backup however Cluster Backup and Restore process mentioned on https://docs.aws.amazon.com/cloudhsm/latest/userguide/create-cluster-from-backup.html doesn't mention the usage of private key to restore the cluster from a backup.

I am confused here if the private key has been used in the backup process or not? If yes, then I foresee some security challenges and concerns to connect offline HSM with AWS platform to make usage of the private key in a back up operation? How can I expose the previously secured private key in a offline HSM to the AWS platform?

Please clarify the usage of Cloud HSM cluster signing private key here.

Thanks

kp
已提問 2 年前檢視次數 119 次
沒有答案

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南