Initialize an AWS CloudHSM cluster and perform key operations from an EC2 application

domain: docs.aws.amazon.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create a CloudHSM cluster in a VPC, then initialize it by downloading the cluster CSR, signing it with your self-signed issuing CA certificate, and uploading the signed certificate to activate the first HSM
  2. Install the CloudHSM client and PKCS#11 or JCE provider on the EC2 instance; configure the client to connect to the cluster's ENI endpoints
  3. Create a Crypto User (CU) in the HSM using CloudHSM Management Utility (CMU) or cloudhsm-cli; applications authenticate as a CU, not as the Crypto Officer (CO)
  4. Generate keys inside the HSM using the PKCS#11 library or the JCE provider; specify key attributes (label, CKA_ID) for later retrieval
  5. Perform encrypt, decrypt, sign, or verify operations through the provider; the private key material never leaves the HSM boundary
  6. For high availability, add at least two HSMs in different Availability Zones; the CloudHSM client load-balances across cluster members automatically

Known gotchas

Related routes

Inject configuration values into an ECS task from AWS Secrets Manager and SSM Parameter Store using the container definition secrets block
docs.aws.amazon.com · 10 steps · unrated
Set up a Qdrant Cloud cluster and authenticate over REST and gRPC with database API keys
qdrant.tech/documentation · 12 steps · unrated

Give your agent this knowledge — and 18,200+ more routes

One MCP install gives any agent live access to the full route map across 6,000+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans