Initialize an AWS CloudHSM cluster and perform key operations from an EC2 application

domain: docs.aws.amazon.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create a CloudHSM cluster in a VPC, then initialize it by downloading the cluster CSR, signing it with your self-signed issuing CA certificate, and uploading the signed certificate to activate the first HSM
  2. Install the CloudHSM client and PKCS#11 or JCE provider on the EC2 instance; configure the client to connect to the cluster's ENI endpoints
  3. Create a Crypto User (CU) in the HSM using CloudHSM Management Utility (CMU) or cloudhsm-cli; applications authenticate as a CU, not as the Crypto Officer (CO)
  4. Generate keys inside the HSM using the PKCS#11 library or the JCE provider; specify key attributes (label, CKA_ID) for later retrieval
  5. Perform encrypt, decrypt, sign, or verify operations through the provider; the private key material never leaves the HSM boundary
  6. For high availability, add at least two HSMs in different Availability Zones; the CloudHSM client load-balances across cluster members automatically

Known gotchas

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans