Supported Hardware Security Modules (HSMs)

The following table lists HSM support for each SignServer deployment option. Integration methods include PKCS #11 standard and REST APIs. SignServer additionally supports software-based keys for lower security requirements or development.

PQC : Indicates PQC algorithm support.

HSM Type

Software stack

Cloud

Software Appliance

Hardware Appliance

Container Set

Network HSMs integrated with REST APIs

Azure Key Vault / MS Managed HSM​

✔️

✔️​
Doc link

✔️
Doc link

Fortanix Data Security Manager (DSM)​ PQC

✔️


✔️

Doc link

Securosys Primus HSM and CloudHSM Service



✔️

Doc link



Network HSMs integrated with PKCS#11

AWS CloudHSM​

✔️

✔️

Doc link

Bull TrustWay Proteccio​

✔️


✔️

Doc link


CloudHSM Service




✔️

Doc link



Entrust nShield Connect​/5c PQC

✔️


✔️

Doc link


Securosys Primus




✔️

Doc link



SoftHSMv2

✔️





✔️

Doc link

Thales DPoD​

✔️


✔️
Doc link


Thales Luna 7 PQC

✔️


✔️
Doc link


✔️​
Doc link

Thales USB HSM




✔️

Doc link



Thales TCT​

✔️


✔️

Doc link


Utimaco CryptoServer​

✔️



✔️
Doc link


✔️​

Doc link

Utimaco u.trust Anchor​ PQC


✔️


✔️

Doc link


Internal Hardware Appliance PCIe HSMs integrated with PKCS#11

Thales Luna PCIe

✔️



✔️

Doc link


Utimaco PCIe

✔️



✔️

Doc link