Introduction

About This Guide

This document serves as the official integration guide for deploying and configuring Qinsight Atlas with the Utimaco u.trust GP HSM. It provides step-by-step instructions for system administrators to establish a secure, mTLS-authenticated connection between the Qinsight platform and the Utimaco HSM using the Utimaco REST Cryptographic API (RCAPI).

Target Audience

This guide is intended for Qinsight Atlas and Utimaco Hardware Security Module (HSM) administrators.

Purpose of the Integration

The primary purpose of this integration is to enable seamless, automated discovery and inventory of hardware-backed cryptographic assets. By integrating Qinsight Atlas with the Utimaco HSM via RCAPI, organizations can:

  • Dynamically fetch metadata for keys and certificates stored securely within the HSM.

  • Automatically generate a comprehensive Cryptographic Bill of Materials (CBOM) for audit and compliance tracking.

  • Continuously monitor cryptographic health, algorithm strength, and key rotation lifecycles - all while ensuring that sensitive private key material never leaves the secure, FIPS-certified boundary of the Utimaco HSM.

Abbreviations

Abbreviation

Meaning

API

Application Programming Interface

Atlas

Qinsight Atlas cryptographic inventory and policy platform

CBOM

Cryptographic Bill of Materials

CET

Central European Time

CN

Common Name

CXI

Cryptographic eXtended Interface

DB

Database

FIPS

Federal Information Processing Standards

GP HSM

General Purpose Hardware Security Module

HA

High Availability

HSM

Hardware Security Module

HTTPS

Hypertext Transfer Protocol Secure

JRE

Java Runtime Environment

MBK

Master Backup Key

mTLS

Mutual Transport Layer Security

P11CAT

PKCS#11 graphical interface tool

PKCS

Public Key Cryptography Standards

PKCS#11

PKCS Part 11: The Cryptographic Token Interface Standard

PKI

Public Key Infrastructure

RCAPI

REST Cryptographic API

REST

Representational State Transfer

RMA

Return Merchandise Authorization

SO

The PKCS#11 cryptographic slot Security Officer

TDE

Transparent Data Encryption

TLS

Transport Layer Security

URL

Uniform Resource Locator

Abbrevations

Document Conventions

The following conventions are used in this guide:

Convention

Use

Example

Bold

Items of the Graphical User Interface (GUI), e.g., menu options

Press OK

Monospaced

Code that is given for explanation or as an example, file paths

/opt/utimaco/bin

Italic

References and important terms

See the given sample: Support - Utimaco Portal

Document conventions

We use special icons to highlight the most important notes and information.

Here you will find important safety information that should be followed.

Here you will find additional notes or supplementary information.

This message indicates the expected result after the successful execution of an instruction.