Can I install RSA Key Recovery Manager without a hardware security module (HSM)?
Originally Published: 2008-11-26
Article Number
Applies To
Redhat Linux Advanced Server 4.0
RSA Key Recovery Manager
Issue
Is it possible to install KRM without an HSM?
Resolution
It is mandatory to use an HSM to do key recovery as the recovery process implies that
1. The private key which should be owned by an end user will now also resides somewhere else, on the HSM
2. That private key can be retrieved by someone which is not the owner, the Key Recovery Operators
Because of those two concepts, the private key must be stored in the most secure way and be also recovered in a secure manner, which the HSM provides.
We do support nCipher nShield and netHSM, and also any PKCS #11-compliant HSM, including the nCipher P11 library. RSA has tested Key Recovery Manager with Safenet Luna SA.
Related Articles
KCA:Problem generating System CA key in SafeNet HSM during CM6.6 setup 2Number of Views Installing Validation Manager 3.0 fails when using an nCipher HSm. 3Number of Views Is SHA-256 supported on RSA_CM with a HSM via P11? 29Number of Views Can the KCA OneStep SSL certificate private key be kept on a HSM? 10Number of Views SAML Enablement Guide for Application Developers 29Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process
Don't see what you're looking for?