This guide provides information on how to configure Oracle Cloud Infrastructure (OCI) to work with the Utimaco Enterprise Secure Key Manager (ESKM) for Hold Your Own Key (HYOK) scenarios. It describes the features and configuration steps in OCI and ESKM that are necessary to establish and validate the integration.
The guide describes the configuration required to securely create and manage cryptographic keys in ESKM while enabling Oracle Cloud Infrastructure Key Management Service (OCI KMS) and supported OCI services to use keys that remain under the control of the ESKM environment.
This guide focuses only on the configuration and integration aspects required for the OCI–ESKM HYOK scenario. It does not provide general installation or administration procedures for OCI or ESKM beyond those required to establish the integration.
For more information on installing and configuring the Utimaco Enterprise Secure Key Manager, refer to the applicable Utimaco Enterprise Secure Key Manager installation and administration documentation.
Target Audience
This guide is intended for Oracle Cloud Infrastructure (OCI) and Utimaco Enterprise Secure Key Manager (ESKM) administrators responsible for configuring and managing the integration between OCI and ESKM.
Purpose of the Integration
The purpose of this integration is to enable Oracle Cloud Infrastructure (OCI) services to use customer-controlled cryptographic keys that are created and securely managed within the Utimaco Enterprise Secure Key Manager (ESKM) while keeping the key material under the control of the ESKM environment.
In the HYOK model, cryptographic keys remain within ESKM and are not uploaded or transferred into Oracle Cloud Infrastructure Key Management Service (OCI KMS). OCI uses a reference to the externally managed key to perform supported cryptographic operations while the key material remains under the control of ESKM.
The integration aims to:
-
Enable OCI services to use customer-controlled cryptographic keys for supported encryption operations.
-
Keep cryptographic key material within the Utimaco ESKM environment.
-
Enable OCI to reference and use externally managed keys without importing the key material into OCI KMS.
-
Provide centralized key management and lifecycle control through Utimaco ESKM.
-
Maintain secure authentication and communication between ESKM and OCI.
-
Support enterprise security and compliance requirements through controlled management of cryptographic material.
Abbreviations
|
Abbreviation |
Meaning |
|---|---|
|
API |
Application Programming Interface |
|
HYOK |
Hold Your Own Key |
|
CA |
Certificate Authority |
|
ESKM |
Enterprise Secure Key Manager |
|
HSM |
Hardware Security Module |
|
IAM |
Identity and Access Management |
|
KMS |
Key Management Service |
|
OCID |
Oracle Cloud Identifier |
|
OCI |
Oracle Cloud Infrastructure |
|
RSA |
Rivest–Shamir–Adleman |
|
TLS |
Transport Layer Security |
Abbreviations
Document Conventions
The following conventions are used in this guide:
|
Convention |
Use |
Example |
|---|---|---|
|
Bold |
Items of the Graphical User Interface (GUI), e.g., menu options |
Press OK |
|
|
Code that is given for explanation or as an example, file paths |
|
|
Italic |
References and important terms |
See Sample Chapter in the CryptoServer - Sample Manual |
Document conventions
We use special icons to highlight the most important notes and information.
Here you will find important safety information that should be followed.
Here you will find additional notes or supplementary information.
This message indicates the expected result after the successful execution of an instruction.