AWS CloudHSM is a cloud-based hardware security module (HSM) that enables generation and use of your own encryption keys on the AWS Cloud.

With CloudHSM:

  • Manage your own encryption keys using FIPS 140-2 Level 3 validated HSMs.
  • Integrate with your applications using industry-standard APIs (such as PKCS#11, Java Cryptography Extensions (JCE), and Microsoft CryptoNG (CNG) libraries).
  • Scale quickly by adding and removing HSM capacity on-demand, with no upfront costs.

CloudHSM is standards-compliant and enables exportation of all of your keys to most other commercially-available HSMs, subject to your configurations. It is a fully-managed service that automates time-consuming administrative tasks (such as hardware provisioning, software patching, high-availability, and backups).

Use the AWS public cloud integration to discover and collect metrics against the AWS service.

External reference

What is AWS CloudHSM?

Setup

To set up the AWS integration and discover the AWS service, go to AWS Integration Discovery Profile and select AWS Cloud HSM.

Event support

CloudTrail event support

  • Supported
  • Configurable in OpsRamp AWS Integration Discovery Profile.

CloudWatch alarm support

  • Supported
  • Configurable in OpsRamp AWS Integration Discovery Profile.

Supported metrics

OpsRamp MetricAWS MetricMetric Display NameUnitAggregation TypeDescription
aws_cloudhsm_HsmUnhealthyHsmUnhealthyHsm UnhealthyNoneAverageThe HSM instance is not performing properly. AWS CloudHSM automatically replaces unhealthy instances for you.
aws_cloudhsm_HsmTemperatureHsmTemperatureHsm TemperatureNoneAverageThe junction temperature of the hardware processor. The system shuts down if temperature reaches 110 degrees Centigrade.
aws_cloudhsm_HsmKeysSessionOccupiedHsmKeysSessionOccupiedHsm Keys Session OccupiedNoneAverageThe number of session keys being used by the HSM instance.
aws_cloudhsm_HsmKeysTokenOccupiedHsmKeysTokenOccupiedHsm Keys Token OccupiedNoneAverageThe number of token keys being used by the HSM instance and the cluster.
aws_cloudhsm_HsmSslCtxsOccupiedHsmSslCtxsOccupiedHsm Ssl Ctxs OccupiedNoneAverageThe number of end-to-end encrypted channels currently established for the HSM instance. Up to 2,048 channels are allowed.
aws_cloudhsm_HsmSessionCountHsmSessionCountHsm Session CountNoneAverageThe number of open connections to the HSM instance.
aws_cloudhsm_HsmUsersAvailableHsmUsersAvailableHsm Users AvailableNoneAverageThe number of additional users that can be created. This equals the maximum number of users (listed in HsmUsersMax) minus the users created to date.
aws_cloudhsm_HsmUsersMaxHsmUsersMaxHsm Users MaxNoneAverageThe maximum number of users that can be created on the HSM instance.
aws_cloudhsm_InterfaceEth2OctetsInputInterfaceEth2OctetsInputInterface Eth2Octets InputNoneAverageThe cumulative sum of incoming traffic to the HSM to date.
aws_cloudhsm_InterfaceEth2OctetsOutputInterfaceEth2OctetsOutputInterface Eth2Octets OutputNoneAverageThe cumulative sum of outgoing traffic to the HSM to date.
aws_cloudhsm_InterfaceEth2DroppedInputInterfaceEth2DroppedInputInterface Eth2Dropped InputNoneAverageInterface Eth2 Packets Input.
aws_cloudhsm_InterfaceEth2DroppedOutputInterfaceEth2DroppedOutputInterface Eth2Dropped OutputNoneAverageInterface Eth2 Packets Output.
aws_cloudhsm_InterfaceEth2ErrorsInputInterfaceEth2ErrorsInputInterface Eth2Errors InputNoneAverageInterface Eth2 Errors Input.
aws_cloudhsm_InterfaceEth2ErrorsOutputInterfaceEth2ErrorsOutputInterface Eth2Errors OutputNoneAverageInterface Eth2 Errors Input.