The following table lists HSM support for each SignServer deployment option. Integration methods include PKCS #11 standard and REST APIs. SignServer additionally supports software-based keys for lower security requirements or development.

pqc : Indicates PQC algorithm support.

HSM Type

Software stack

Cloud

Software Appliance

Hardware Appliance

Container Set

Network HSMs integrated with REST APIs

Azure Key Vault / MS Managed HSM​

(tick)

(tick)
Doc link

(tick)
Doc link

Fortanix Data Security Manager (DSM)​ pqc

(tick)

(tick)

Doc link

Securosys Primus HSM and CloudHSM Service

(tick)

Doc link

Network HSMs integrated with PKCS#11

AWS CloudHSM​

(tick)

(tick)

Doc link

Bull TrustWay Proteccio​

(tick)

(tick)

Doc link

CloudHSM Service

(tick)

Doc link

Entrust nShield Connect​/5c pqc

(tick)

(tick)

Doc link

Securosys Primus

(tick)

Doc link

SoftHSMv2

(tick)

(tick)

Doc link

Thales DPoD​

(tick)

(tick)
Doc link

Thales Luna 7 pqc

(tick)

(tick)
Doc link

(tick)
Doc link

Thales USB HSM

(tick)

Doc link

Thales TCT​

(tick)

(tick)

Doc link

Utimaco CryptoServer​

(tick)

(tick)
Doc link

(tick)

Doc link

Utimaco u.trust Anchor​ pqc

(tick)

(tick)

Doc link

Internal Hardware Appliance PCIe HSMs integrated with PKCS#11

Thales Luna PCIe

(tick)

(tick)

Doc link

Utimaco PCIe

(tick)

(tick)

Doc link