Skip to content

Initialization of an AWS CloudHSM consists of the following steps:

  1. Initialize the cluster.
  2. Update the users.
  3. Create the wrapping key label.

For guidance on these tasks, see the AWS CloudHSM documentation.

Prerequisites

To initialize an AWS CloudHSM, you need a minimum of two AWS CloudHSM instances deployed in a single or multi-AWS HSM cluster, according to the vendor instructions.

Initialize the cluster

Initialize the cluster with private Certificate Authority tools.

Update the users

Update the cluster users as follows:

  1. Bootstrap the root user.
  2. Create a user to manage the vault.

Create the wrapping key label

In the cluster, create an AES (advanced encryption standard) wrapping key label to act as a key identifier, with encrypt and decrypt capabilities.