Initialization of an AWS CloudHSM consists of the following steps:
- Initialize the cluster.
- Update the users.
- Create the wrapping key label.
For guidance on these tasks, see the AWS CloudHSM documentation.
To initialize an AWS CloudHSM, you need a minimum of two AWS CloudHSM instances deployed in a single or multi-AWS HSM cluster, according to the vendor instructions.
Initialize the cluster with private Certificate Authority tools.
Update the cluster users as follows:
- Bootstrap the root user.
- Create a user to manage the vault.
In the cluster, create an AES (advanced encryption standard) wrapping key label to act as a key identifier, with encrypt and decrypt capabilities.