{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/deployment/reference/kms-notary","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/deployment/reference/kms-notary","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/deployment/reference/kms-notary","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/deployment/reference/kms-notary","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/deployment/reference/kms-notary","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/deployment/reference/kms-notary","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition","tabs","tab"]},"type":"markdown"},"seo":{"title":"Notary configuration","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"notary-configuration","__idx":0},"children":["Notary configuration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this page to understand the Notary configuration fields for ","Ripple Custody",". The examples show possible configuration shapes; your KMS platform, credentials, certificates, resource values, and rollout process depend on your deployment."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This page applies to on-premise deployments only. For current defaults and the full supported schema, use the configuration packaged with your release."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-this-config-controls","__idx":1},"children":["What this config controls"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Notary handles approval signing through a KMS or HSM backend. The Vault uses the Notary public key to verify Notary signatures."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"protocol-fields","__idx":2},"children":["Protocol fields"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Location: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["harmonize.notary"]}]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Parameter"},"children":["Parameter"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Default"},"children":["Default"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["protocol"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["grpc"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Communication protocol between Notary Bridge and Notary. Possible values: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["grpc"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Protocol notes:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Protocol"},"children":["Protocol"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Notes"},"children":["Notes"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["grpc"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Supports gRPC communication between Notary Bridge and Notary."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Supports HTTP communication between Notary Bridge and Notary."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"component-fields","__idx":3},"children":["Component fields"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Location: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["components.notary"]}]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["platform"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Selects the KMS/HSM backend used by the Notary."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["resources"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["CPU and memory requests and limits for the Notary component."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["persistence"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Persistent state configuration, where exposed by your release."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["env"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Environment-variable overrides exposed by your release."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["<platform configuration>"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Platform-specific configuration block, such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_ibm"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Image references, internal ports, and inter-service wiring are managed by the release package unless explicitly exposed."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"platform-values","__idx":4},"children":["Platform values"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform value"},"children":["Platform value"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["luna"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms-luna"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Hardware HSM"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Thales Luna HSM through KMS Connect."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_blocksafe"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms-blocksafe"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Hardware HSM"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["BlockSafe HSM through KMS Connect."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_ibm"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Hardware HSM"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["IBM LinuxONE or IBM Hyper Protect Crypto Services integration."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_securosys"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms-securosys"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Hardware HSM"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Securosys Primus HSM through KMS Connect."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"platform-specific-fields","__idx":5},"children":["Platform-specific fields"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Luna HSM","disable":false},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.host"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Luna HSM hostname or IP address."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.port"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Luna HSM port. Common value: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["1792"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.slot"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["HSM partition slot number."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.pin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["HSM partition password."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.client.certificate"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client certificate for mutual TLS."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.client.key"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client private key for mutual TLS."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.server.certificate"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Luna HSM server certificate."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_luna.existingSecret"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Existing secret containing Luna credentials and certificates."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["existingSecret"]}," is set for Luna HSM, the secret must contain these keys:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Secret key"},"children":["Secret key"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["pin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["HSM partition password."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client-cert"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client certificate."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client-key"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client private key."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["server-cert"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server certificate."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Inline ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["pin"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client.certificate"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client.key"]},", and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["server.certificate"]}," values are ignored when ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["existingSecret"]}," is set."]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"BlockSafe HSM","disable":false},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_blocksafe.device"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["BlockSafe device connection string. Existing format: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["port@host"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_blocksafe.slot"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["HSM slot number."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_blocksafe.pin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["HSM PIN."]}]}]}]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"IBM LinuxONE / HPCS","disable":false},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_ibm.system"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["IBM system type."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_ibm.instance"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["IBM instance identifier or CRN."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_ibm.endpoint"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["IBM endpoint."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_ibm.apikey"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["IBM API key."]}]}]}]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Securosys Primus HSM","disable":false},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_securosys.host"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Securosys Primus HSM host."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_securosys.port"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Securosys Primus HSM port."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_securosys.user"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Securosys user."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["kms_securosys.setupPassword"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Securosys setup password."]}]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"constraints-and-relationships","__idx":6},"children":["Constraints and relationships"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The Notary should use a platform value supported by the KMS/HSM integration you deploy."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The Vault needs the Notary public key in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["harmonize.vaults.<vault-id>.notary_public_key"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The Notary public key is returned during Genesis. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/install/first-time-installation"},"children":["Installation and initialization"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The Notary and Vault KMS choices should be planned together. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/planning/key-management"},"children":["Key management planning"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"example","__idx":7},"children":["Example"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This example shows a Notary configured with Luna HSM and an existing secret:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"harmonize:\n  notary:\n    protocol: grpc\n  vaults:\n    \"00000000-0000-0000-0000-000000000000\":\n      notary_public_key: \"ed25519:<notary-public-key>\"\n\ncomponents:\n  notary:\n    platform: kms_luna\n    kms_luna:\n      host: \"luna-hsm.example.com\"\n      port: \"1792\"\n      slot: \"0\"\n      existingSecret: \"notary-luna-credentials\"\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"related-topics","__idx":8},"children":["Related topics"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/reference/kms-vault"},"children":["Vault configuration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/reference/networking"},"children":["Networking configuration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/planning/key-management"},"children":["Key management planning"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/thales-luna"},"children":["Luna HSM integration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/cloud-hsm/aws-cloudhsm"},"children":["AWS CloudHSM integration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/blocksafe"},"children":["BlockSafe HSM integration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/ibm-linuxone"},"children":["IBM HPCS integration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/mpc/overview"},"children":["MPC integration"]}]}]}]},"headings":[{"value":"Notary configuration","id":"notary-configuration","depth":1},{"value":"What this config controls","id":"what-this-config-controls","depth":2},{"value":"Protocol fields","id":"protocol-fields","depth":2},{"value":"Component fields","id":"component-fields","depth":2},{"value":"Platform values","id":"platform-values","depth":2},{"value":"Platform-specific fields","id":"platform-specific-fields","depth":2},{"value":"Constraints and relationships","id":"constraints-and-relationships","depth":2},{"value":"Example","id":"example","depth":2},{"value":"Related topics","id":"related-topics","depth":2}],"frontmatter":{"seo":{"title":"Notary configuration"}},"lastModified":"2026-08-04T20:25:11.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/deployment/reference/kms-notary","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}