---
title: "Fortanix DSM with Delinea Secret Server"
slug: "fortanix-dsm-using-delinea-secret-server"
updated: 2026-07-08T17:09:07Z
published: 2026-07-08T17:09:07Z
canonical: "support.fortanix.com/fortanix-dsm-using-delinea-secret-server"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM with Delinea Secret Server

## 1.0 Introduction

This article describes how to integrate **Fortanix-Data-Security-Manager (DSM)** with **Delinea Secret Server** to protect encryption key using Fortanix DSM.

## 2.0 Prerequisites

Ensure the following:

- The Fortanix CNG Client must be installed and configured.
- Port 443 must be accessible from the SQL target machine to Fortanix DSM.

| Protocol | Inbound/ Outbound | Port Number | Load balancer (Yes/No) | Purpose |
| --- | --- | --- | --- | --- |
| **TCP** | Outbound | 443 | No | HTTPS – Used for calling the REST API. Delinea server will access the cluster/SaaS URL on this port. Each individual node will also need this port open. |

## 3.0 Configure Fortanix DSM

A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:

### 3.1 Signing Up

To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, [https://amer.smartkey.io.](https://amer.smartkey.io.) On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map) based on the application region.

*For more information on how to set up the Fortanix DSM, refer to the* [*Sign Up for Fortanix Data Security Manager SaaS*](https://support.fortanix.com/docs/users-guide-sign-up-for-fortanix-data-security-manager-saas)*.*

### 3.2 Creating an Account

Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DSM_SaaS_Login_page(15).png)

**Figure 1: Logging in**

*For more information on how to set up an account in Fortanix DSM, refer to the* [*Getting Started with Fortanix Data Security Manager - UI*](https://support.fortanix.com/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*

### 3.3 Creating a Group

Perform the following steps to create a group in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Groups** menu item, and then click **ADD GROUP** to create a new group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-Group(66).png)

**Figure 2: Add groups**
2. On the **Adding new group** page:
  1. **Title**: Enter a name for your group.
  2. **Description** (optional): Enter a short description of the group.
3. Click **SAVE** to create the new group.

*For more information about groups, refer to* [*Definitions*](/v1/docs/dsm-definitions#40-groups)*.*

> [!NOTE]
> TIP
> 
> It is recommended to configure a **Key undo policy** for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured **Key undo policy**, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. *For detailed steps, refer to* [*Key Undo Policy*](/v1/docs/fortanix-dsm-key-undo-policy)*.*

### 3.4 Creating an Application

Perform the following steps to create an application (app) in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click **ADD APP** to create a new app.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-App(64).png)

**Figure 3: Add application**
2. On the **Adding new app** page:
  1. **App name**: Enter the name for your application.
  2. **ADD DESCRIPTION** (optional): Enter a short description of the application.
  3. **Authentication method**: Select the default **API Key** as the authentication method from the drop down menu. *For more information on these authentication methods, refer to the* [*User's Guide: Authentication*](https://support.fortanix.com/docs/users-guide-authentication)*.*
  4. **Assigning the new app to groups**: Select the group created in [*Section 3.3: Creating a Group*](/v1/docs/fortanix-data-security-manager-using-delinea-secret-server#33-creating-a-group) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#43-creating-a-group)from the list.
3. Click **SAVE** to add the new application.

*For more information about applications, refer to* [*Definitions*](https://support.fortanix.com/docs/dsm-definitions#50-applications)*.*

### 3.5 Copying the API Key

Perform the following steps to copy the API key from the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click the app created in [*Section 3.4: Creating an Application*](/v1/docs/integration-guide-quick-snippets#creating-an-application) to go to the detailed view of the app.
2. On the **INFO** tab, click **VIEW API KEY DETAILS**.
3. From the **API Key Details** dialog box, copy the **API Key** of the app to use in [*Section 4.2: Configuring CNG Client*](/v1/docs/fortanix-data-security-manager-using-delinea-secret-server#42-configuring-cng-client).

## 4.0 Fortanix CNG Provider

The Fortanix CNG Provider must be installed on every target machine. *Refer to* [*Fortanix CNG/EKM*](https://fortanix.zendesk.com/hc/en-us/sections/27488968118932-CNG-EKM) *to download the CNG Provider.*

`FortanixKmsClient.msi` installs the Fortanix CNG Provider, as well as an EKM provider and the PKCS#11 library. Next, to configure the CNG client, Fortanix CNG Provider communicates with Fortanix DSM for crypto operations.

### 4.1 Installing Fortanix CNG Client

Perform the following steps to complete the installation on your machine:

1. On the **Fortanix KMS Client Setup** dialog box, click **Next**.

![Image1.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18994870228244.png)

**Figure 4: Fortanix KMS client setup**
2. Select the check box for **I accept the terms in the License Agreement** and click **Next**.

![Image2.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18994870229396.png)

**Figure 5: Fortanix KMS client setup**
3. Enter the location for installing the **Fortanix KMS Client** as `C:\Program Files\Fortanix\KMS Client\`.

![Image3.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18994917310228.png)

**Figure 6: Fortanix KMS client setup**
4. Click **Install** to install the Fortanix KMS client.

![Image4.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18994917311252.png)

**Figure 7: Fortanix KMS client setup**
5. After the installation is done, click **Finish**.

![Image5.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18994917312276.png)

**Figure 8: Fortanix KMS client setup**

### 4.2 Configuring CNG Client

The Fortanix KMS Server URL and proxy information are configured in the Windows registry for the local machine or the current user.

1. Run the following command to navigate to `FortanixKmsClientConfig.exe` file:

```bash
cd C:\Program Files\Fortanix\KmsClient\
```

The machine key store uses the local machine configuration, and the user key store uses the current user configuration. For example, run the following command to configure the Fortanix KMS Server URL for the local machine:

```bash
FortanixKmsClientConfig.exe machine --api-endpoint {KMS_URL}
```

Where,

`KMS_URL` refers to the Fortanix DSM URL. On-premises customers use KMS URL and SaaS customers can use the URLs based on the region. DSM SaaS supports multiple regions, as listed [*here*](https://support.fortanix.com/docs/fortanix-dsm-saas-global-availability-map).

For example,

```bash
FortanixKmsClientConfig.exe machine --api-endpoint https://<fortanix_dsm_url>
```
2. Run the following command to configure the Fortanix KMS Server URL for the current user:

```bash
FortanixKmsClientConfig.exe user --api-endpoint {KMS_URL}
```

To configure proxy information, add `--proxy http://proxy.com` or `--proxy none` to unconfigure proxy.
3. Run the following command to configure the API key as copied in [*Section 3.5: Copying the API Key*](/v1/docs/fortanix-data-security-manager-using-delinea-secret-server#35-copying-an-api-key):

```bash
FortanixKmsClientConfig.exe machine --api-key <key>
```
4. Run the following command for the user key store:

```bash
FortanixKmsClientConfig.exe user --api-key <key>
```

## 5.0 Enable Fortanix HSM

Perform the following steps to enable Fortanix HSM:

1. Log in to the **Delinea Secret Server**.
2. From the left pane menu, select **Administration** → **Actions** → **Configuration** → **HSM**. The **Configuration** page appears on the screen with the **HSM** tab selected by default.
3. Click **Enable HSM** and then click **Next**.

![Enable-HSM.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/21108845653140.png)

**Figure 9: Enable HSM configuration**
4. Under the **HSM Providers** section:
  1. For **Persistent Provider**, select e**Fortanix KMS CNG Provider** from the drop down menu.

![Select-Provider.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18995631341588.png)

**Figure 10: Select provider**
  2. Select the required **Key size**. For example, `2048`.
5. Click **Next**. The HSM provider is tested, and the results are displayed on the screen.
6. Check the **HSM Provider Test Results**. For example,

![Test-Results.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18995647400724.png)

**Figure 11: Test results**
7. Click **Next**. A verification page appears on the screen.
8. Click **Save** to update the HSM configuration. A confirmation page appears on the screen.
9. Click **Finish**.

![Confgurations.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18995664139028.png)

**Figure 12: Configured provider**

The Fortanix KMS CNG Provider is now enabled, and the Secret Server encryption key is stored in it. The configuration details appear on the Secret Server **HSM** tab.

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.

## Related

- [Fortanix DSM with BeyondTrust Password Safe](/fortanix-dsm-with-beyondtrust-password-safe.md)
