Target audience: Cloud Architects, DevOps
Focus: HSM integration, Secrets Management, Multi-Cloud
Integration of PQ-enabled PKI with cloud HSM and secrets management services.
| Feature | Azure Key Vault | AWS KMS | HashiCorp Vault |
| ——— | —————– | ——— | —————– |
| HSM FIPS 140-2 | Level 3 (Managed HSM) | Level 3 (CloudHSM) | Level 2 (Transit) |
| PQ Support | Not yet | Not yet | Via plugins |
| Cert Management | Native | ACM | PKI Engine |
| Multi-Cloud | No | No | Yes |
| Cost | Medium | High (CloudHSM) | Open Source + Enterprise |
| Scenario | Cloud | HSM Type |
|---|---|---|
| Azure Key Vault | Azure | Managed HSM |
| AWS KMS + CloudHSM | AWS | CloudHSM |
| HashiCorp Vault | Multi-Cloud | Transit SE |
Recommendation: On-premises Root CA + Cloud Intermediate for cloud workloads
| Component | Location | Rationale |
| ———– | ———- | ———– |
| Root CA | On-premises (HSM) | Highest security |
| Intermediate (Cloud) | Azure/AWS/Vault | Proximity to workloads |
| End Entity | Cloud | Auto-provisioning |
| Backup | Multi-Cloud | Disaster recovery |
« <- Operator Scenarios | -> Azure Key Vault »
Wolfgang van der Stille @ EMSR DATA d.o.o. - Post-Quantum Cryptography Professional