Overview
OpenSSL is an open-source project that consists of a cryptographic library and an SSL/TLS toolkit. OpenSSL provides command-line tools for cryptographic operations including symmetric encryption, public-key encryption, and digital signing hash.
Thales ProtectServer 3 HSMs can be used to securely store OpenSSL cryptographic keys. OpenSSL integrates with GemEngine to allow the consumption of HSM resources. The benefits of using ProtectServer 3 HSMs to generate the cryptographic keys for OpenSSL are the following:
-
Secure generation, storage, and protection of the identity-signing private key on FIPS-validated hardware.
-
Full life-cycle management of the keys.
-
Significant performance improvements by offloading cryptographic operations from application servers.