---
title: "Fortanix DSM with IDcentral Key Management"
slug: "fortanix-dsm-with-idcentral-key-management"
updated: 2026-08-19T14:26:29Z
published: 2026-08-19T14:26:29Z
canonical: "support.fortanix.com/fortanix-dsm-with-idcentral-key-management"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM with IDcentral Key Management

## 1.0 Introduction

This article describes the configuration steps required on **Fortanix-Data-Security-Manager (DSM)** and **Sixscape’s IDcentral Key Management** platform to securely escrow S/MIME encryption key pairs using Sixscape Email Security Suite and IDcentral Identity Registration platform.

## 2.0 Prerequisites

This integration requires the following:

- Fortanix PKCS#11 client. You can download the latest version from [*here*](/v1/docs/pkcs-11).
- Fortanix API Key to configure IDcentral Key Management Platform.
- IDcentral Identity Registration Platform (IRP) installed in the enterprise network and configured with the required issuing CA connection and certificate profile to generate the S/MIME certificates.
- IDcentral Key Management must be installed and configured with IDcentral IRP.
- End-user devices should be installed with Sixscape’s Email Security Suite Add-In.

## 3.0 Architecture Workflow

The following image illustrates the workflow:

![Archi-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568937997716.png)

**Figure 1: DSM with IDcentral workflow**

## 4.0 Configure Fortanix DSM

A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:

### 4.1 Signing Up

To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, [https://amer.smartkey.io.](https://amer.smartkey.io.) On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map) based on the application region.

*For more information on how to set up the Fortanix DSM, refer to* [*Sign Up for Fortanix Data Security Manager SaaS*](https://support.fortanix.com/docs/users-guide-sign-up-for-fortanix-data-security-manager-saas)*.*

### 4.2 Creating an Account

Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DSM_SaaS_Login_page(15).png)

**Figure 2: Logging in**

*For more information on how to set up an account in Fortanix DSM, refer to* [*Getting Started with Fortanix Data Security Manager - UI*](https://support.fortanix.com/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*

### 4.3 Creating a Group

Perform the following steps to create a group in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Groups** menu item, and then click **ADD GROUP** to create a new group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-Group(79).png)

**Figure 3: Add groups**
2. On the **Adding new group** page:
  1. **Title**: Enter a name for your group.
  2. **Description** (optional): Enter a short description of the group.
3. Click **SAVE** to create the new group.

*For more information about groups, refer to* [*Definitions*](/v1/docs/dsm-definitions#40-groups)*.*

> [!NOTE]
> TIP
> 
> It is recommended to configure a **Key undo policy** for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured **Key undo policy**, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. *For detailed steps, refer to* [*Key Undo Policy*](/v1/docs/fortanix-dsm-key-undo-policy)*.*

### 4.4 Creating an Application

Perform the following steps to create an application (app) in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click **ADD APP** to create a new app.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-App(69).png)

**Figure 4: Add application**
2. On the **Adding new app** page:
  1. **App name**: Enter the name for your application.
  2. **ADD DESCRIPTION** (optional): Enter a short description of the application.
  3. **Authentication method**: Select the default **API Key** as the authentication method from the drop down menu. *For more information on these authentication methods, refer to the* [*User's Guide: Authentication*](https://support.fortanix.com/docs/users-guide-authentication)*.*
  4. **Assigning the new app to groups**: Select the group created in [*Section 4.3: Creating a Group*](/v1/docs/fortanix-dsm-with-idcentral-key-management#43-creating-a-group) from the list.
3. Click **SAVE** to add the new application.

*For more information about applications, refer to* [*Definitions*](https://support.fortanix.com/docs/dsm-definitions#50-applications)*.*

### 4.5 Copying the API Key

Perform the following steps to copy the API key from the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click the app created in [*Section 4.4: Creating an Application*](/v1/docs/fortanix-dsm-with-idcentral-key-management#44-creating-an-application) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#44-creating-an-application)to go to the detailed view of the app.
2. On the **INFO** tab, click **VIEW API KEY DETAILS**.
3. From the **API Key Details** dialog box, copy the **API Key** of the app to use it later.

## 5.0 Configure PKCS#11

Perform the following steps to configure PKCS#11 on your system:

1. Install the Fortanix PKCS#11 client in the Windows server where the IDcentral Key Management is installed.
2. Configure the Fortanix PKCS#11 client using the steps described in [*Clients: PKCS#11 Library*](https://support.fortanix.com/docs/clients-pkcs11-library).

## 6.0 Configure IDcentral Key Management

The following sections describe the steps required to integrate IDcentral Key Management with Fortanix DSM.

### 6.1 Configuring Crypto Token

Perform the following steps to add the Fortanix DSM as a PKCS#11 cryptographic token in IDcentral Key Management:

1. Log in to the **IDcentral Key Management Snap-In**, navigate to **Crypto Tokens** to add a new token.

![AddToken-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568937999892.png)

**Figure 5: Add new token**
2. On the **Add Token Configuration** page, select the key store type as **HSM PKCS#11 Keystore** and enter a name for the token configuration.
3. Click the **file upload** icon to browse the Fortanix DSM PKCS#11 DLL file.
4. After the correct DLL file is selected, the list of available token slots is listed under the **Token** drop down menu. Select the required token slot.
5. Enter the **Token PIN**. This value is the Fortanix DSM API Key created in [*Section 4.5: Copying the API Key*](/v1/docs/fortanix-dsm-with-idcentral-key-management#45-copying-the-api-key)*.*
6. Click **Save** to save the configuration.

![TokenConfiguration-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568938000532.png)

**Figure 6: Token configuration**

### 6.2 Creating Encryption Key Manager

This section describes the steps to create and activate an Encryption Key Manager (EKM) after the cryptographic token is added to IDcentral Key Management. This process involves creating an asymmetric key pair and a certificate for the key manager in the Fortanix DSM. The end-user’s S/MIME encryption keys are securely wrapped and escrowed using the Key Manager’s keypair, which is securely protected within the Fortanix DSM.

Perform the following steps to add a new Key Manager:

1. Log in to **IDcentral Key Management Snap-In**, navigate to **Key Managers**→**Add Key Manager**.
2. Enter a name for the key manager in the **Manager Name** field.
3. Enter a subject distinguished name (DN) for the Key Manager in the **General Information** section.

> [!NOTE]
> NOTE
> 
> This configuration will be used later in the steps to generate the CSR for the Key Manager.
4. In the **Private Key Specification** section, select **Encryption** as the **Intended Purpose** of the Key Manager.
5. From the **Key Algorithm** drop down menu, select the appropriate key algorithm.
6. From the **Key store type** drop down menu, select **HSM PKCS#11 Keystore**, and select the newly added Fortanix DSM Keystore in the **Keystore** field.
7. Click **Save** and provide the Keystore PIN, which is the Fortanix DSM PKCS#11 PIN (API Key) to successfully create the Key Manager.

![AddKeyManager-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568921847572.png)

**Figure 7: Add key manager**
8. After the Key Manager is added successfully, click **Download CSR** to export the PEM CSR file for the newly created encryption Key Manager.

![DownloadCSR-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568921847828.png)

**Figure 8: Download CSR**

You should also be able to view the newly generated Security-object in the **Security Objects** table in Fortanix DSM user interface (UI).

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1768858566486.png)

**Figure 9: DSM security key object**

### 6.3 Activating Encryption Key Manager

This section describes the steps to activate the encryption key manager by requesting a digital certificate from a CA and importing it into Fortanix DSM. The issuance of the key manager certificate by the CA is out of the scope of this article. *Refer to the respective CA documentation on how to request a digital certificate for a Key Escrow Manager from the CA.*

> [!NOTE]
> NOTE
> 
> Ensure that the issued certificate has the **Key Encipherment** key usage enabled.

1. After the certificate has been generated, log in to the **IDcentral Key Management**, navigate to **Key Managers**, select the key manager, and then click **View**.
2. Click **Upload Certificate** and select the certificate file to import the key manager certificate.

![UploadCertificate-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568921849236.png)

**Figure 10: Import key manager certificate**

A prompt is displayed on the screen for the keystore PIN. Provide the Fortanix DSM PKCS#11 PIN (API Key) to authenticate and reassociate the certificate with the keypair of the key manager.
3. After the successful import of the certificate, the new encryption key manager will be activated and is ready to receive secure key escrow and key recovery requests from clients.

![Certificate-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568921850644.png)

**Figure 11: Encryption key manager activated**

> [!NOTE]
> NOTE
> 
> Ensure that the Key Management Service is restarted from “services.msc” for the changes to take effect. Additionally, ensure that the IDcentral registration service is also synchronized with the newly created Key Manager configuration.

## 7.0 Certificate Enrolment using Email Security Suite

After the necessary backend configurations have been completed, end-user devices can be provisioned with Sixscape’s Email Security Suite (ESS). ESS is available for all major operating system platforms, enabling enterprise users to seamlessly request S/MIME certificates for secure, digitally signed, and encrypted email communication. ESS automates the complete lifecycle management of S/MIME digital certificates, including certificate requests, renewals, key storage, key escrow, and revocation.

This article focuses on ESS for Microsoft Outlook on the Windows platform. Note that the deployment of ESS to user’s devices is beyond the scope of this article. For technical assistance with deployment, contact your respective system administrator.

After the successful deployment of ESS to the user’s device, the ESS ribbon is displayed in the Outlook Explorer ribbon, as shown in the following image:

![ESSRibbon-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568955424020.png)

**Figure 12: ESS ribbon**

Perform the following steps:

1. Compose a new email to any recipient and click **Send**.
2. The ESS Add-in, at this stage, automatically identifies if you have a valid S/MIME certificate to digitally sign and encrypt the email and will prompt the user to request a new S/MIME certificate.
3. Click **Request Certificate**.

![RequestCertificate-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568929917460.png)

**Figure 13: Request digital certificate**
4. In the next screen, authenticate using your enterprise authentication credentials, such as your Active Directory credentials.

![CertAuth-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568982400404.png)

**Figure 14: Authentication details**
5. After the authentication is successful, ESS will automatically generate key pairs and a CSR as specified in the certificate profile, and the CSR will be submitted to IDcentral IRP to request the S/MIME certificate from the configured certifying authority.
6. After the certificate is received, ESS will reassociate the certificate with the key pair, publish the public certificate to the Global Address Book, securely escrow the encryption key and certificate using the Encryption Key Manager protected by Fortanix DSM, and finally install the certificate in the user certificate store as non-exportable.
7. After the entire certificate process is completed, click **Done**, and send the first signed email.

![CertInstalled-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568982401556.png)

**Figure 15: Certificate installed**
8. The escrowed user’s encryption keys can be located under the **Key Archives** section of IDcentral Key Management Service.

![KeyArchives-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568963625236.png)

**Figure 16: Encryption keys**

> [!NOTE]
> NOTE
> 
> Repeat all these *Steps 1-8* on the other devices and platforms to recover the newly created key and certificate securely and automatically from the Escrow Key Manager protected by Fortanix DSM.

## 8.0 Manual Recovery by Administrator

According to organizational policies or the law, enterprises must keep the email communications of their former employees for a specific amount of time for legal and compliance purposes. This, in turn, means that any encrypted data, including encrypted email communications, must be recoverable while simultaneously being protected from unauthorized access. Furthermore, the loss of the private key could result in data loss; hence, a secure escrow mechanism should be set up to seamlessly and securely protect the email encryption keys and certificates. Security can be further enhanced by enabling hardware-based security, such as a hardware security module (HSM), to protect the encryption private keys.

Sixscape’s IDcentral Key Management, integrated with Fortanix DSM, enables a secure escrow mechanism to seamlessly protect the email encryption private keys of users. Wrapping them in an Escrow Key Manager key and certificate—both of which are secure within the Fortanix DSM—accomplishes this.

This section outlines the steps for manually recovering the full key history of an end-user if the employee has left the organization.

1. Log in to **IDcentral Key Management Administrator Snap-In** and navigate to **Key Archives**.
2. Type the relevant email address in the **Search Bar** to look for the user’s key archive.
3. Select the user’s record to expand and view the key history.

![KeyArchives-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568995568660.png)

**Figure 18: Key History**
4. Click the **Recover** icon in the header row to export the complete key history to a single PKCS#12 file.

> [!NOTE]
> NOTE
> 
> If a single key pair needs to be exported, select the individual records from the exported list and click the corresponding **Recover** Icon.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/RecoverIcon-IDC(1).png)

**Figure 18: Export key history**
5. Enter the Fortanix DSM Keystore PIN (API Key) and click **OK**.

![RecoverAPIKey-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18569013180692.png)

**Figure 19: Keystore PIN**
6. After the authentication is successful, the administrator will be prompted to set a passphrase for the exported PKCS#12.

![Passphrase-IDC.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/18568970719764.png)

**Figure 20: Passphrase**

The exported PKCS#12 will be successfully recovered and exported to the `C:\Users\Pubic\SixEscrow\ClientPKCS12s` directory.

## 

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.

A security object is any datum stored in DSM (for example a key, a certificate, a password, or other security objects). Each security object is assigned to exactly one group. users and applications assigned to the group have permission to see the security object and to perform operations on it.

## Related

- [Getting Started with Fortanix DSM - UI](/getting-started-with-fortanix-data-security-manager-ui.md)
