Overview
Integration between ProtectServer 3 HSMs and Apache Tomcat uses the Java JCE/JCA interface to generate the SSL keys on ProtectServer 3 HSMs. ProtectServer 3 HSMs integrate with Apache Tomcat to generate 2048 bit RSA key pairs for SSL, and provide security by protecting the private keys and certificate within a FIPS-validated hardware security module.
The benefits of using ProtectServer 3 HSMs to generate the SSL keys for Apache Tomcat include the following:
-
Secure generation, storage, and protection of the SSL keys on FIPS-validated hardware.
-
Full life-cycle management of the keys.
-
Significant performance improvements by offloading cryptographic operations from servers.
About Apache Tomcat
Apache Tomcat is an open source implementation of the Java Servlet, JavaServer Pages, Java Expression Language, and Java WebSocket technologies. The Java Servlet, JavaServer Pages, Java Expression Language, and Java WebSocket specifications are developed under the Java Community Process.
Apache Tomcat is developed in an open and participatory environment and released under the Apache License version 2. The Apache Tomcat project is intended to be a collaboration of the best-of-breed developers from around the world. Apache Tomcat software powers numerous large-scale, mission-critical web applications across a diverse range of industries and organizations. Apache Tomcat provides a "pure Java" HTTP web server environment in which Java code can run.
The Thales HSM solution for Apache Tomcat provides secure key management as well as SSL acceleration and provides extra security by protecting and managing the server’s SSL private key within a FIPS-validated HSM.