Overview

Product video
Entrust (Formerly HyTrust) KeyControl provides Enterprise Grade Key Management for on premise or multi-cloud virtual infrastructure. Deploy a single KeyControl node within minutes using the KeyControl solution in the AWS Marketplace. Then form a cluster by deploying additional nodes and joining them to your original node/cluster. Entrust KeyControl cluster is highly secure, scalable, FIPS certified, highly available, fully symmetric cluster which can scale up to 8 geographically distributed nodes. Use instructions in the KeyControl Admin guide to configure your newly deployed KeyControl cluster as your key manage to manage Keys in Multi-Cloud and virtualized encrypted workload environments with KeyControl. Search entrust.com/documentation for instructions on how to integrate KeyControl with Entrust partner products.
Highlights
- Zero-downtime Encryption: Keep applications online during initial encryption and re-keying operations.
- Policy-based Key Management: Entrust KeyControl is secure and highly available, ensuring you have complete control over your encryption keys.
- Simplicity: You want security without complexity. DataControl can be deployed in seconds and its policy-based operation requires very little ongoing management.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
t3.large Recommended | $0.80 |
t2.micro | $0.80 |
c3.xlarge | $0.80 |
c4.xlarge | $0.80 |
d2.xlarge | $0.80 |
t2.2xlarge | $0.80 |
t2.medium | $0.80 |
i3.xlarge | $0.80 |
m5a.large | $0.80 |
m5ad.xlarge | $0.80 |
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
What's changed in KCV 10.5.1 (CSP 1.3)
- Licenses are now enforced in the Cryptographic Security Platform Vault. You will see pop-up warnings in the webGUI when there are important issues with your license.
- Expanded support for Post Quantum Encryption and Key Management including support for ML-KEM, ML-DSA and SLH-DSA keys, as well as encapsulation, decapsulation, sign and verify operations using these key types. Also added improved PQ security for KMIP Server with support for PQ-TLS.
- You can now use KeySafe5 (part of the CSP appliance) to monitor your nShield HSM when configured with the Cryptographic Security Platform Vault. Note: You can view the KeySafe5 GUI through the Cryptographic Security Platform Compliance Manager.
- The Cryptographic Security Platform Vault for Cloud Keys now supports on demand key rotation for AWS key versions with BYOK.
Additional details
Usage instructions
Access KeyControl console please SSH to your KeyControl server's public ip with your public key using login ID "htadmin" and the initial password is the Amazon instance ID for the KeyControl instance. Access to the Entrust system is through any standard browser using public ip of your KeyControl. During install, a single administrator is created called secroot with a password which is the Amazon instance ID for the KeyControl instance. After logging in for the first time, you will be presented with the EULA (one time only).
Resources
Support
Vendor support
https://trustedcare.entrust.com/ Please allow 24 hours for a response when contacting Entrust. For customers interested in an Enterprise Support Contract, please contact Entrust Sales.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
