See the following table for the Hardware Security Module (HSM) versions supported by each solution.

Hardware

Client driver

Firmware

Certificate Authority

Timestamping Authority

Validation Authority

Entrust nShield Connect XC

13.9.0 (FIPS 140-2 Level 3 mode supported)

12.60.15 & 12.60.2

(tick) 

(tick) 

(tick) 

Entrust nShield 5c

13.9.0

13.2.4

(tick) 

(tick) 

(tick) 

Epicom

 EP990 v1.08-1

(error) 

(tick) 

(tick) 

Thales Luna HSM 7

10.8.0

7.7.1-20

(tick) 

(tick) 

(tick) 

Thales TCT

10.8.0

7.7.1-20

(error)  

(tick) 

(tick) 

General considerations:

  • You do not need to install the client drivers because the solution already includes this software. However, these client drivers cannot be updated.
  • You can only use 1/N card sets. A card set of, for example, 2/5 cards is not supported.
  • On high-availability installations with a cluster of several HSMs:

    • You cannot use HSMs from different providers simultaneously, meaning that nShield and Thales HSMs cannot coexist within the same deployment.
    • Entrust Validation Authority may experience the Thales TCT limitations described in the Thales TCT Universal Client Plugin Additional Information technical note dated May 28, 2025.
    • Solutions using the HSMs must be redeployed after any loss of connection with the HSMs, such as after an HSM reboot.