Skip to content

ezSign Key Management

ezSign Key Management keeps each organization's signing keys safe on secure hardware (a hardware security module, or HSM) and performs the signing operation using them. This is what makes ezSign signatures qualified under the EU eIDAS framework.

It is a behind-the-scenes service that works together with the Signing Service. You never use it directly.

What it does

  • Keeps signing keys on secure hardware - private keys never leave the HSM and are never exposed.
  • Performs the signing using those keys, on behalf of the Signing Service.
  • Keeps each organization separate - every organization's keys are isolated.

Good to know

  • It is managed for you. {{ product_name }} runs and configures Key Management; there is nothing for everyday users to do.
  • Your keys stay protected. Because signing happens inside secure hardware, the private key is never handed out.

More detail coming

A fuller description of Key Management will be added here. For how signing works today, see the Signing Service.

FAQ

Where are my organization's signing keys kept?

On secure hardware (an HSM) managed by {{ product_name }}. The private key never leaves the hardware and is never exposed.

Do I need to manage keys myself?

No. Key Management is run and configured by {{ product_name }}. There is nothing for everyday users to set up.