---
title: "Fortanix DSM with Skyhigh Secure Web Gateway (SWG)"
slug: "fortanix-dsm-with-skyhigh-secure-web-gateway-swg"
updated: 2026-07-30T08:43:53Z
published: 2026-07-30T08:43:53Z
canonical: "support.fortanix.com/fortanix-dsm-with-skyhigh-secure-web-gateway-swg"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM with Skyhigh Secure Web Gateway (SWG)

## 1.0 Introduction

This article describes how to integrate **Fortanix-Data-Security-Manager (DSM)** with **Skyhigh Secure Web Gateway (SWG)** to deliver Hardware Security Module (HSM) capabilities. The HSM serves the purpose of safeguarding private keys utilized in SSL communication.

After it is installed, the HSM assumes responsibility for private key operations associated with the keys under its protection. To facilitate seamless integration with the hardware module, HSM software is installed on the Web Gateway.

## 2.0 Prerequisites

Ensure the following:

- Command Line Interface (CLI) accessibility.
- Secure Web Gateway v12.2.3 is supported.

## 3.0 Configure Fortanix DSM

A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:

### 3.1 Signing Up

To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, [https://amer.smartkey.io.](https://amer.smartkey.io.) On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map) based on the application region.

*For more information on how to set up the Fortanix DSM, refer to the* [*Sign Up for Fortanix Data Security Manager SaaS*](https://support.fortanix.com/docs/users-guide-sign-up-for-fortanix-data-security-manager-saas)*.*

### 3.2 Creating an Account

Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DSM_SaaS_Login_page(15).png)

**Figure 1: Logging in**

*For more information on how to set up an account in Fortanix DSM, refer to the* [*Getting Started with Fortanix Data Security Manager - UI*](https://support.fortanix.com/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*

### 3.3 Creating a Group

Perform the following steps to create a group in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Groups** menu item, and then click **ADD GROUP** to create a new group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-Group(79).png)

**Figure 2: Add groups**
2. On the **Adding new group** page:
  1. **Title**: Enter a name for your group.
  2. **Description** (optional): Enter a short description of the group.
3. Click **SAVE** to create the new group.

*For more information about groups, refer to* [*Definitions*](/v1/docs/dsm-definitions#40-groups)*.*

> [!NOTE]
> TIP
> 
> It is recommended to configure a **Key undo policy** for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured **Key undo policy**, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. *For detailed steps, refer to* [*Key Undo Policy*](/v1/docs/fortanix-dsm-key-undo-policy)*.*

### 3.4 Creating an Application

Perform the following steps to create an application (app) in the Fortanix DSM:

1. In the DSM UI left navigation panel, click the **Apps** menu item, and then click **ADD APP** to create a new app.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-App(6).png)

**Figure 3: Add application**
2. On the **Adding new app** page:
  1. **App name**: Enter the name for your application.
  2. **ADD DESCRIPTION** (optional): Enter a short description of the application.
  3. **Authentication method**: Select the default **API Key** as the authentication method from the drop down menu. *For more information on these authentication methods, refer to the* [*User's Guide: Authentication*](https://support.fortanix.com/docs/users-guide-authentication)*.*
  4. **Assigning the new app to groups**: Select the group created in [*Section 3.3: Creating a Group*](/v1/docs/using-fortanix-data-security-manager-with-skyhigh-secure-web-gateway-swg#33-creating-a-group) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#43-creating-a-group)from the list.
3. Click **SAVE** to add the new application.

*For more information about applications, refer to* [*Definitions*](https://support.fortanix.com/docs/dsm-definitions#50-applications)*.*

### 3.5 Copying the API Key

Perform the following steps to copy the API key from the Fortanix DSM:

1. In the DSM UI left navigation panel, click the **Apps** menu item, and then click the app created in [*Section 3.4: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-with-skyhigh-secure-web-gateway-swg#34-creating-an-application) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#44-creating-an-application)to go to the detailed view of the app.
2. On the **INFO** tab, click **VIEW API KEY DETAILS**.
3. From the **API Key Details** dialog box, copy the **API Key** of the app to use it later.

### 3.6 Updating the Client Configuration Settings

Perform the following steps:

1. In the DSM UI left navigation panel, click the **Settings** menu item, and then click the **CLIENT CONFIGURATION** tab.
2. In the **COMMON** tab, select **Logging** → **File** and update the file log **Path** to `/opt/mwg/log/debug/fortanix/fortanix.log`.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Client Configuration Screen(1).png)

**Figure 4: Add path**

## 4.0 Load the Private Key Identifiers

This section describes the steps to enumerate the available keys in the SWG user interface (UI).

Perform the following steps to enable SWG to utilize keys within Fortanix DSM:

1. Open the Skyhigh Secure Web Gateway UI.
2. Navigate to **Configuration** → **Appliances** → **Hardware Security Module**.

![figure 1.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645242524180.png)

**Figure 5: Hardware Security Module**
3. Select the **Start local HSM server** check box.

![figure 2.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645242530964.png)

**Figure 6: HSM Server**
4. From the **Crypto Module** drop down menu, select **Fortanix DSM (from Fortanix)**.

![figure 3.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645242534420.png)

**Figure 7: Select Module**
5. Enter the **Fortanix DSM API key** and click **Set** to confirm. *To learn about this app API key, refer to* [*Section 3.5: Copying the API Key*](/v1/docs/using-fortanix-data-security-manager-with-skyhigh-secure-web-gateway-swg#35-copying-the-api-key)*.*

![figure 4.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645242536980.png)

**Figure 8: Enter Fortanix DSM API Key**
6. Enter the Fortanix DSM app API Key as a **Password** and click **OK**.

![figure 6.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645214045076.png)

**Figure 9: Enter Password**

To modify the Fortanix DSM app API Key, select **Change**.

![figure 7.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/23374428091668.png)

**Figure 10: Modify Fortanix DSM API Key**
7. In the **Keys to be loaded** section, click **+** to add the key as a string.

![figure 8.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/23374350860692.png)

**Figure 11: Add Keys**
8. The format for adding keys is `&lt;engine-label&gt;:&lt;pkcs11-URI&gt;`.
  - The engine-label should be "pkcs11" to inform SWG that these are PKCS#11 keys.
  - Enter the key as a string using the format: `pkcs11:pkcs11:object=&lt;key&gt;`. The value of 'Key' is based on the Key Label name created in Fortanix DSM UI.

![figure 9.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645242592532.png)

**Figure 12: Add the String**

## 5.0 Create Certificate Using Fortanix DSM Private Keys

You can create certificates seamlessly in SWG using Fortanix DSM private keys by setting up the app API key and executing OpenSSL commands through CLI access.

Perform the following steps:

1. Open the SWG console through the CLI.
2. In the root directory, create a new file named `fortanix.cfg` to store the `API_KEY` value as created in [*Section 3.5: Copying the API Key*](/v1/docs/using-fortanix-data-security-manager-with-skyhigh-secure-web-gateway-swg#45-copying-an-api-key):

```bash
api_key = "API_KEY"
```
3. Run the following command to provide the required permissions:

```bash
chmod 777 fortanix.cfg
```
4. Run the following commands to export the file:

```bash
# export FORTANIX_PKCS11_NUM_SLOTS=1
# echo $FORTANIX_PKCS11_NUM_SLOTS 1
```
5. Use the following OpenSSL commands:

```bash
openssl1.1
OpenSSL> engine -pre MODULE_PATH:/opt/fortanix/pkcs11/fortanix_pkcs11.so -pre VERBOSE pkcs11
```

This command generates the following sample output:

![figure 10.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645214063252.png)

**Figure 13: Sample Output**
6. Run the following OpenSSL "req" command to generate the certificate:

```bash
OpenSSL> req -engine pkcs11 -keyform engine -new -key "pkcs11:object=<key>;pin-value=file:///root/fortanix.cfg" -x509 -days 3650 -out FILENAME.crt -set_serial 0xdeadbeef
```

This command successfully creates the certificate file.

![figure 11.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/22645242587924.png)

**Figure 14: Certificate Generated**

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.

## Related

- [SDKs for REST API](/fortanix-dsm-clients-sdks-for-rest-api.md)
- [Fortanix DSM with Snowflake for Tokenization](/fortanix-dsm-with-snowflake.md)
