Utimaco Enterprise Secure Key Manager (ESKM) and Bloombase StoreSafe Integration

Bloombase supports Utimaco ESKM out of the box due to the fact that both products support OASIS Key Management Interoperability Protocol (KMIP).

To enable the built-in Bloombase KeyCastle to utilize keys managed in the network attached Utimaco ESKM, the KMIP service configuration at Bloombase web management console has to be set up. This is done by clicking “OASIS KMIP Key Manager” under “Key Management”.

tmpy20eqbcc.jpg

Input a name for the configuration, and select Model as

Utimaco ESKM

Input also the host address and port to access the Utimaco ESKM, and import the signed X.509 key pair as “Client Keystore”, the certificate of the local root CA on Utimaco ESKM as “Trust Certificate”.

tmp1z9zm192.jpg

X.509 key pair CN=bloombase01 is generated and signed by the root CA in the Utimaco ESKM, and assigned as the client authentication key pair for Bloombase StoreSafe.

tmp6kdux1bl.jpg

Click ‘Submit’ to commit the configuration. If the certificates are setup properly, “test results” of the KMIP Key Manager would return “Success”.