Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SThornell
New Contributor

Retrieve ML-KEM keys from an external HSM using KMIP for secure PQC key exchange on IPSEC VPN

Hi, 

 

Is it possible to retrieve the ML-KEM keys from an external HSM using KMIP? I've been reading this article, Post-Quantum Cryptography for IPsec key exchange NEW | FortiGate / FortiOS 7.6.1 | Fortinet Document...

 

We currently have the ability to retrieve the IPSEC SA key from an external HSM using KMIP, IPsec SA key retrieval from a KMS server using KMIP | FortiGate / FortiOS 7.4.0 | Fortinet Document .... However it would be great to be able to retrieve the ML-KEM keys as well. Is this supported? If so is there a configuration guide or some guidance you could offer?

3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello SThornell, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Regards,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Regards,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again,

 

I found this solution. Can you tell me if it helps, please?

 

Currently, the provided context does not specify support for retrieving ML-KEM keys from an external HSM using KMIP. The context mentions the ability to retrieve IPsec SA keys from a KMS server using KMIP, but it does not explicitly state support for ML-KEM keys. For further guidance or confirmation, it would be best to consult the latest Fortinet documentation or contact Fortinet support directly.

Regards,

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors