---
name: hs-crypto-sitemap
title: Site map
description: Find what you are looking for in the compilation of topics that are available in this documentation set.
last-updated: 2024-08-22
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/hs-crypto?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Site map
{: #sitemap}

Find what you are looking for in the compilation of topics that are available in this documentation set.
{: shortdesc}







## Getting started
{: #sitemap_getting_started}


[Getting started with IBM Cloud Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#get-started)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#get-started-prerequisites)

* [Step 1: Initialize your service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#initialize-crypto)

* [Step 2 (Standard Plan only): Create keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#create-key-standard)

* [Step 2 (Unified Key Orchestrator Plan only): Manage your encryption keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#manage-uko-key)

* [Step 3: Encrypt your data with cloud HSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#encrypt-data-hsm)


## Understanding Hyper Protect Crypto Services Standard Plan
{: #sitemap_understanding_hyper_protect_crypto_services_standard_plan}


[Overview - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-overview&format=markdown#overview)

* [Why IBM Cloud Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-overview&format=markdown#why_hpcs)

* [How does Hyper Protect Crypto Services work?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-overview&format=markdown#how-hpcs-work)

* [Key features](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-overview&format=markdown#key-features)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-overview&format=markdown#overview-next)

[Service architecture - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-architecture-workload-isolation&format=markdown#architecture-workload-isolation)

* [Hyper Protect Crypto Services architecture](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-architecture-workload-isolation&format=markdown#architecture)

* [Hyper Protect Crypto Services workload isolation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-architecture-workload-isolation&format=markdown#workload-isolation)

* [Service dependencies](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-architecture-workload-isolation&format=markdown#service_dependencies)

[Use cases - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-use-cases&format=markdown#use-cases)

* [Pervasively protecting data at rest in the cloud](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-use-cases&format=markdown#data-at-rest-encryption)

* [Using Hyper Protect Crypto Services as a cloud HSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-use-cases&format=markdown#cloud_hsm)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-use-cases&format=markdown#use-case-next)

[Components and concepts - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-understand-concepts&format=markdown#understand-concepts)

* [Key management service](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-understand-concepts&format=markdown#key-management-concepts)

* [Cloud hardware security module](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-understand-concepts&format=markdown#cloud-hsm-concepts)


### About service instance initialization - Standard Plan
{: #sitemap_about_service_instance_initialization_standard_plan}


[Initializing your service instance - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-service&format=markdown#introduce-service)

* [Understanding administrators and signature keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-service&format=markdown#understand-crypto-unit-admin)

* [Understanding imprint mode and signature thresholds](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-service&format=markdown#understand-imprint-mode)

* [Understanding the master key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-service&format=markdown#understand-key-ceremony)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-service&format=markdown#introduce-instance-initialization-next)

[Introducing service instance initialization approaches - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-instance-mode&format=markdown#initialize-instance-mode)

* [Initializing service instances by using smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-instance-mode&format=markdown#instance-initialization-management-utilities)

* [Initializing service instances by using recovery crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-instance-mode&format=markdown#instance-initialization-recovery-crypto-unit)

* [Initializing service instances by using key part files](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-instance-mode&format=markdown#instance-initialization-key-files)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-instance-mode&format=markdown#initialize-instance-mode-next)


### About key management service - Standard Plan
{: #sitemap_about_key_management_service_standard_plan}


[Bringing your encryption keys to the cloud - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-importing-keys&format=markdown#importing-keys)

* [Planning ahead for importing key material](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-importing-keys&format=markdown#plan-ahead)

* [Using import tokens](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-importing-keys&format=markdown#using-import-tokens)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-importing-keys&format=markdown#importing-keys-next)

[Protecting your data with envelope encryption - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-envelope-encryption&format=markdown#envelope-encryption)

* [Keys in envelope encryption](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-envelope-encryption&format=markdown#key-types)

* [How it works](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-envelope-encryption&format=markdown#envelope-encryption-overview)

* [Wrapping keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-envelope-encryption&format=markdown#wrapping)

* [Unwrapping keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-envelope-encryption&format=markdown#unwrapping)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-envelope-encryption&format=markdown#envelope-encryption-next)

[Monitoring the lifecycle of encryption keys - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-key-states&format=markdown#key-states)

* [Key states and transitions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-key-states&format=markdown#key-transitions)

* [Key states and service actions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-key-states&format=markdown#key-states-service-actions)

* [Monitoring for lifecycle changes](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-key-states&format=markdown#monitor-lifecycle-changes)


### About cloud hardware security module - Standard Plan
{: #sitemap_about_cloud_hardware_security_module_standard_plan}


[Introducing cloud HSM - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-cloud-hsm&format=markdown#introduce-cloud-hsm)

* [What is cloud HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-cloud-hsm&format=markdown#what-is-cloud-hsm)

* [Performing cryptographic operations by accessing the cloud HSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-cloud-hsm&format=markdown#cryptography-cloud-hsm)

[Introducing PKCS #11 - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-intro&format=markdown#pkcs11-intro)

* [PKCS #11 implementation components](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-intro&format=markdown#pkcs11-components)

* [Post-quantum cryptography support](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-intro&format=markdown#pkcs11-support-post-quantum)

[Introducing EP11 over gRPC - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-intro&format=markdown#grep11-intro)

* [Post-quantum cryptography support](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-intro&format=markdown#grep11-support-post-quantum)


### About key rotation - Standard Plan
{: #sitemap_about_key_rotation_standard_plan}


[Master key rotation - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-master-key-rotation-intro&format=markdown#master-key-rotation-intro)

* [How master key rotation works](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-master-key-rotation-intro&format=markdown#how-master-key-rotation-works)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-master-key-rotation-intro&format=markdown#master-key-rotation-next)

[Root key rotation - Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-root-key-rotation-intro&format=markdown#root-key-rotation-intro)

* [Comparing your root key rotation options](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-root-key-rotation-intro&format=markdown#compare-key-rotation-options)

* [How root key rotation works](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-root-key-rotation-intro&format=markdown#how-root-key-rotation-works)

* [Frequency of root key rotation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-root-key-rotation-intro&format=markdown#rotation-frequency)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-root-key-rotation-intro&format=markdown#root-key-rotation-next)


### About Bring Your Own HSM  - Standard Plan
{: #sitemap_about_bring_your_own_hsm_standard_plan}


[Introducing Bring Your Own HSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-bring-your-own-hsm&format=markdown#introduce-bring-your-own-hsm)

* [What is Bring Your Own HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-bring-your-own-hsm&format=markdown#what-is-byohsm)

* [How to enable Bring Your Own HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-bring-your-own-hsm&format=markdown#how-to-enable-byohsm)

* [Limitations and scope](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-bring-your-own-hsm&format=markdown#byohsm-limitation-scope)

* [Responsibilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-bring-your-own-hsm&format=markdown#byohsm-responsibility)


## Understanding Hyper Protect Crypto Services with Unified Key Orchestrator Plan
{: #sitemap_understanding_hyper_protect_crypto_services_with_unified_key_orchestrator_plan}


[Overview - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-overview&format=markdown#uko-overview)

* [Why IBM Cloud Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-overview&format=markdown#uko-why_hpcs)

* [Why Unified Key Orchestrator?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-overview&format=markdown#why-uko)

* [Key features](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-overview&format=markdown#uko-key-features)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-overview&format=markdown#uko-overview-next)

[Service architecture - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-architecture-workload-isolation&format=markdown#uko-architecture-workload-isolation)

* [Hyper Protect Crypto Services architecture](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-architecture-workload-isolation&format=markdown#uko-architecture)

* [Hyper Protect Crypto Services workload isolation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-architecture-workload-isolation&format=markdown#uko-workload-isolation)

* [Service dependencies](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-architecture-workload-isolation&format=markdown#uko-service_dependencies)

[Use cases - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-use-cases&format=markdown#uko-use-cases)

* [Pervasively protecting data at rest in the cloud](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-use-cases&format=markdown#uko-data-at-rest-encryption)

* [Using Unified Key Orchestrator for multicloud key orchestration](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-use-cases&format=markdown#uko-use-case)

* [Using Hyper Protect Crypto Services as a cloud HSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-use-cases&format=markdown#uko-cloud_hsm)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-use-cases&format=markdown#uko-use-case-next)

[Components and concepts](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-understand-concepts&format=markdown#uko-understand-concepts)

* [Key management service](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-understand-concepts&format=markdown#uko-key-management-concepts)

* [Cloud hardware security module](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-understand-concepts&format=markdown#uko-cloud-hsm-concepts)

* [Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-understand-concepts&format=markdown#uko-unified-key-orchestrator-concepts)


### About service instance initialization - Unified Key Orchestrator Plan
{: #sitemap_about_service_instance_initialization_unified_key_orchestrator_plan}


[Initializing your service instance - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-service&format=markdown#uko-introduce-service)

* [Understanding administrators and signature keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-service&format=markdown#uko-understand-crypto-unit-admin)

* [Understanding imprint mode and signature thresholds](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-service&format=markdown#uko-understand-imprint-mode)

* [Understanding the master key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-service&format=markdown#uko-understand-key-ceremony)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-service&format=markdown#uko-introduce-instance-initialization-next)

[Introducing service instance initialization approaches - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-initialize-instance-mode&format=markdown#uko-initialize-instance-mode)

* [Initializing service instances by using smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-initialize-instance-mode&format=markdown#uko-instance-initialization-management-utilities)

* [Initializing service instances by using recovery crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-initialize-instance-mode&format=markdown#uko-instance-initialization-recovery-crypto-unit)

* [Initializing service instances by using key part files](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-initialize-instance-mode&format=markdown#uko-instance-initialization-key-files)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-initialize-instance-mode&format=markdown#uko-initialize-instance-mode-next)


### About Unified Key Orchestrator
{: #sitemap_about_unified_key_orchestrator}


[Introducing Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-uko&format=markdown#introduce-uko)

* [Use case example](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-uko&format=markdown#uko-use-case-example)

* [Components](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-uko&format=markdown#Components)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-introduce-uko&format=markdown#uko-next)

[Monitoring the lifecycle of encryption keys in Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-key-states&format=markdown#uko-key-states)

* [Key states and transitions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-key-states&format=markdown#uko-key-transitions)

* [Key states and service actions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-key-states&format=markdown#uko-key-states-service-actions)

* [Monitoring for lifecycle changes](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-key-states&format=markdown#uko-monitor-lifecycle-changes)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-key-states&format=markdown#uko-key-states-next)


### About cloud hardware security module - Unified Key Orchestrator Plan
{: #sitemap_about_cloud_hardware_security_module_unified_key_orchestrator_plan}


[Introducing cloud HSM - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-cloud-hsm&format=markdown#uko-introduce-cloud-hsm)

* [What is cloud HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-cloud-hsm&format=markdown#uko-what-is-cloud-hsm)

* [Performing cryptographic operations by accessing the cloud HSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-introduce-cloud-hsm&format=markdown#uko-cryptography-cloud-hsm)

[Introducing PKCS #11 - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-pkcs11-intro&format=markdown#uko-pkcs11-intro)

* [PKCS #11 implementation components](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-pkcs11-intro&format=markdown#uko-pkcs11-components)

* [Post-quantum cryptography support](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-pkcs11-intro&format=markdown#uko-pkcs11-support-post-quantum)

[Introducing EP11 over gRPC - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-grep11-intro&format=markdown#uko-grep11-intro)

* [Post-quantum cryptography support](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-grep11-intro&format=markdown#uko-grep11-support-post-quantum)


### About key rotation - Unified Key Orchestrator Plan
{: #sitemap_about_key_rotation_unified_key_orchestrator_plan}


[Master key rotation - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-master-key-rotation-intro&format=markdown#uko-master-key-rotation-intro)

* [How master key rotation works](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-master-key-rotation-intro&format=markdown#uko-how-master-key-rotation-works)

* [How keys are protected during master key rotation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-master-key-rotation-intro&format=markdown#uko-how-master-key-protect-rotation)

* [How the UI reflects master key rotation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-master-key-rotation-intro&format=markdown#uko-how-console-display-progress)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-master-key-rotation-intro&format=markdown#uko-master-key-rotation-next)

[Managed key rotation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managed-key-rotation-intro&format=markdown#managed-key-rotation-intro)

* [How managed key rotation works](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managed-key-rotation-intro&format=markdown#how-managed-key-rotation-works)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managed-key-rotation-intro&format=markdown#managed-key-rotation-next)


## Managing regulated workloads with Hyper Protect Crypto Services
{: #sitemap_managing_regulated_workloads_with_}


[Managing regulated workloads with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-regulated-workloads&format=markdown#manage-regulated-workloads)

* [Encrypting your regulated workloads with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-regulated-workloads&format=markdown#encrypt-regulated-workloads)

* [Regulated workloads use cases](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-regulated-workloads&format=markdown#regulated-workloads-use-cases)

* [Getting started to manage your regulated workloads with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-regulated-workloads&format=markdown#get-started-regulated-workloads)

* [Reference](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-regulated-workloads&format=markdown#reference-regulated-workloads)


## Integrating IBM Cloud services with Hyper Protect Crypto Services
{: #sitemap_integrating_services_with_}


[Integrating IBM Cloud services with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#integrate-services)

* [Storage service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#storage-integration)

* [Database service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#database-integration)

* [Compute service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#compute-integration)

* [Container service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#container-integration)

* [Ingestion service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#Ingestion-integrations)

* [Security service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#security-service-integrations)

* [Developer tools service integrations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#devtools-integrations)

* [Understanding your integration](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#understand-integration)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-integrate-services&format=markdown#integration-next-steps)


## Security and compliance
{: #sitemap_security_and_compliance}


[Security and compliance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-security-and-compliance&format=markdown#security-and-compliance)

* [Security readiness](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-security-and-compliance&format=markdown#security-ready)

* [Compliance readiness](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-security-and-compliance&format=markdown#compliance-ready)


## Release notes
{: #sitemap_release_notes}


[Release notes](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#what-new)

* [18 July 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-july182024)

    * Updated: Transition to VPC data centers in Dallas, Washington D.C, and Frankfurt

* [15 July 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-july152024)

    * Updated: New API endpoints in Frankfurt

* [2 July 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-july22024)

    * Updated: New API endpoints in Madrid

* [19 June 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-june192024)

    * Updated: New API endpoints in Tokyo

* [5 June 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-june2024)

    * Updated: New API endpoints in London

* [29 May 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-may292024)

    * Updated: New API endpoints in Toronto

* [15 May 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-may152024)

    * Updated: New API endpoints in S&atilde;o-Paulo

* [8 May 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-may2024)

    * Updated: New API endpoints in Dallas

* [12 April 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-apr2024)

    * Updated: New API endpoints in Washington DC

* [29 February 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-feb2024)

    * Added: New key state `pending destruction` 

    * Added: Connecting to Azure Key Vault through private endpoint

* [18 January 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-jan2024)

    * Added: Azure software-protected key support for IBM Cloud

* [09 November 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-nov2023)

    * Added: Hyper Protect Crypto Services adds support for Bring Your Own HSM (BYOHSM)

* [26 October 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-26oct2023)

    * Deprecated: IBM Cloud Hyper Protect Crypto Services in Sydney

* [22 Sept 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-sept2023)

    * Added: Hyper Protect Crypto Services expands into the Madrid region 

* [3 August 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-august2023)

    * Added: Key template support for Unified Key Orchestrator 

* [1 June 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-june2023)

    * Updated: Pricing plan for Unified Key Orchestrator 

* [24 May 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-may2023)

    * Updated: Master key rotation support for all regions

* [24 March 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-march2023)

    * Added: Master key rotation for Unified Key Orchestrator

    * Added: Master key rotation for EP11 keystores

* [1 Feb 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-feb2023)

    * Added: Hyper Protect Crypto Services key management functions 

    * Added: Activity Tracker event names

* [19 December 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-dec2022)

    * Added: Managed key rotation support for Unified Key Orchestrator

* [21 November 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-nov2022)

    * Added: Management Utilities support for Red Hat Enterprise Linux 9.0 and Ubuntu 22.04.1 LTS

* [31 October 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-31oct2022)

    * Added: Google Cloud KMS support

* [20 October 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-20oct2022)

    * Added: EP11 activity tracker events

* [24 June 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-24june2022)

    * Added: Go SDK and Terraform support for Unified Key Orchestrator

* [8 June 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-8june2022)

    * [Added: Post-quantum cryptography support](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-pqc)

* [3 June 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-3june2022)

    * [Added: Hyper Protect Crypto Services Unified Key Orchestrator CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-uko-cli)

* [1 April 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-1april2022)

    * [Updated: Pricing model of the Hyper Protect Crypto Services standard plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#update-pricing-model)

    * [Updated: Process of ordering smart cards and smart card readers](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#update-smartcard-procurement)

* [25 March 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-25mar2022)

    * [Added: Hyper Protect Crypto Services expands into the Toronto region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-toronto-region)

* [22 March 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-march2022)

    * General availability: Using Unified Key Orchestrator to manage and orchestrate keys in a multicloud environment 

* [28 February 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-28feb2022)

    * [Limited availability: Using Unified Key Orchestrator to manage and orchestrate keys in a multicloud environment](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-uko})

* [23 February 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-23feb2022)

    * [Added: Using IBM Cloud Monitoring to measure Hyper Protect Crypto Services metrics](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-monitoring-metrics)

* [15 February 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-15feb2022)

    * [Added: Hyper Protect Crypto Services expands into the S&atilde;o-Paulo region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-sao-region)

* [21 January 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-jan2022)

    * [Updated: Hyper Protect Crypto Services key management functions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#update-kms-api-v282)

* [30 July 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-july2021)

    * [Added: Exclusive control on the execution of cryptographic operations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-cert-manager)

    * [Added: Hyper Protect Crypto Services expands into the Tokyo region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-tokyo-region)

    * [Added: Using Terraform to initialize the Hyper Protect Crypto Services instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-terraform-automation)

    * [Added: Using a signing service to manage signature keys for instance initialization](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-signing-service)

* [30 June 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-june2021)

    * [Added: Authenticated PKCS #11 keystore](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-authenticated-pkcs11-keystore)

    * [Added: Enabling cross-region recovery with failover crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-failover-crypto-units)

    * [Added: Hyper Protect Crypto Services expands into the London region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-london-region)

* [30 April 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-april2021)

    * [Added: Rotating your master key by using smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-master-key-rotation-smart-cards)

    * [Updated: Restore key API and UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#update-restore-key-api-ui)

* [31 March 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-march2021)

    * [Added: Grouping keys by using key rings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-key-ring)

    * [Added: Initializing the service instance by using recovery crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-recovery-crypto-units)

    * [Added: Managing EP11 keystores and keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-ep11-keystores-keys-console)

    * [Added: Managing key aliases for a key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-key-alias)

    * [Added: Synchronizing protected resources associated with root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-sync-resources)

    * [Added: Using Virtual Private Endpoints for VPC](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-vpe-for-vpc)

    * [Updated: The cryptography algorithm that is used to generate signature keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#update-signature-key-algorithm)

* [28 February 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-february2021)

    * [Added: Key verification by using the PKCS #11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-key-verification)

    * [Added: Support for the Schnorr algorithm](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-schnorr)

* [31 January 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-january2021)

    * [Added: Support for a single-tenant KMIP adapter](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-support-kmip-adapter)

* [31 December 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-december2020)

    * [Added: Managing the key create and import access policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-key-create-import-access)

    * [Added: Provisioning and managing service instances with the private-only network](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-private-only-network)

    * [Added: `ReencryptSingle` function in GREP11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-reencryptsingle-function-grep11)

    * [Added: Support for accessing service instances through the Virtual Private Endpoint](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-vpe)

    * [Added: Support for the SLIP10 mechanism and Edwards-curve algorithm](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-slip10-eddsa)

    * [Added: Using Terraform to manage Hyper Protect Crypto Services instances and resources](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-terraform)

    * [Updated: key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#update-kms-api-december)

* [30 November 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-november2020)

    * [Added: Support for the BIP32 mechanism](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-bip32-mechanism)

    * [Added: TKE activity tracker events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#add-tke-at-events)

* [30 September 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-september2020)

    * [Added: Master key rotation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-master-key-rotation)

    * [Added: Support for performing cryptographic operations with the standard PKCS #11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-pkcs11)

* [31 August 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-august2020)

    * [Added: Support for import tokens to securely upload encryption keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-import-tokens)

* [31 July 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-july2020)

    * [Added: Hyper Protect Crypto Services aligns the key management functions with Key Protect](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-key-protect-concurrency)

    * [Added: Hyper Protect Crypto Services expands into the Washington DC region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-wdc-region)

* [30 June 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-june2020)

    * [Added: Support for quorum authentication](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-quorum-authentication-202006)

* [30 April 2020](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-april2020)

    * [Added: Hyper Protect Crypto Services adds support for EP11 private endpoints](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-private-endpoints-202004)

    * [Added: Hyper Protect Crypto Services adds support for the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-management-utilities-202004)

    * [Updated: IBM Cloud service integration](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-service-integration-202004)

* [31 August 2019](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-August2019)

    * [Added: Hyper Protect Crypto Services adds support for private endpoints](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-private-endpoints)

    * [Added: Hyper Protect Crypto Services Cloud HSM now supports EP11 cryptographic operations over gRPC](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-EP11)

    * [Added: Hyper Protect Crypto Services expands into the Frankfurt region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-frankfurt-region)

    * [Added: IBM Cloud service integration](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-service-integration)

* [30 June 2019](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-June2019)

    * [Added: Hyper Protect Crypto Services expands into Sydney region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#added-sydney-region)

* [31 March 2019](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-March2019)

    * [Hyper Protect Crypto Services is generally available](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#ga-201903)

    * [High availability and disaster recovery](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#ha-dr-new)

    * [Scalability](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#scalability-new)

* [28 February 2019](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-Feb2019)

    * [Hyper Protect Crypto Services Beta is available](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#beta-201902)

* [31 December 2018](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hs-crypto-Dec2018)

    * [Added: Integration of Key Protect API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#kp-api)

    * [Added: Support for HSM management with Keep Your own Key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#hsm-kyok)

    * [Deprecated: Function of accessing Hyper Protect Crypto Services through Advanced Cryptography Service Provider](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-what-new&format=markdown#deprecated-acsp)


## Tutorials on key management service
{: #sitemap_tutorials_on_key_management_service}


[Creating and importing encryption keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-keys)

* [Objectives](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-objectives)

* [Task flow](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-flow)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-prereqs)

* [Create an import token](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-create-token)

* [Retrieve the import token](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-retrieve-token)

* [Create an encryption key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-create-key)

* [Set the encryption key as an environment variable](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-env-variable)

* [Encrypt the nonce with the encryption key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-encrypt-nonce)

* [Encrypt the created encryption key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-encrypt-key)

* [Import the encrypted key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-encrypted-key)

* [Clean up](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-clean-up)

* [Next steps](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-import-keys&format=markdown#tutorial-import-next-steps)

[Configuring KMIP for key management and distribution in Hyper Protect Crypto Services Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-vmware)

* [Objectives](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-objectives)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-prerequisites)

* [Task flow](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-steps)

* [Grant the service-to-service authorization in IAM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-s2s)

* [Configure KMIP for VMWare with Hyper Protect Crypto Services instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-vmware-configure)

* [Configure a trusted connection between the vCenter Server and KMIP adapter](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-verify)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-kmip-vmware&format=markdown#tutorial-kmip-next)


## Tutorials on cloud hardware security module
{: #sitemap_tutorials_on_cloud_hardware_security_module}


[Using Hyper Protect Crypto Services PKCS #11 for Oracle Transparent Database Encryption](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-pkcs11)

* [Objectives](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-objectives)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-prerequisites)

* [Task flow](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-steps)

* [Initialize your Hyper Protect Crypto Services instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-initialize)

* [Set up the Hyper Protect Crypto Services PKCS #11 library in your Oracle Database environment](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-pkcs11-setup)

* [Set up Oracle Database TDE and encrypt your data](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-dte-encrypt)

* [Next steps](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-tde-pkcs11&format=markdown#tutorial-tde-summary)

[Using Hyper Protect Crypto Services PKCS #11 for IBM Db2 native encryption](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-pkcs11)

* [Objectives](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-objectives)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-prerequisites)

* [Task flow](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-steps)

* [Initialize your Hyper Protect Crypto Services instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-initialize)

* [Set up the Hyper Protect Crypto Services PKCS #11 library](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-pkcs11-setup)

* [Set up Db2 native encryption](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-encrypt)

* [Next steps](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-db2-pkcs11&format=markdown#tutorial-db2-summary)


## Tutorials on Unified Key Orchestrator
{: #sitemap_tutorials_on_unified_key_orchestrator}


[Using Hyper Protect Crypto Services with Unified Key Orchestrator to manage keys in Key Protect on Satellite](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite)

* [Objectives](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-objectives)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-prerequisites)

* [Task flow](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-steps)

* [Deploy Key Protect on Satellite](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-deploy-kp)

* [Connect Unified Key Orchestrator to Key Protect on Satellite](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-connect-uko-kp)

* [Manage Key Protect keys through Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-manage-kp-keys)

* [Next steps](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-uko-satellite&format=markdown#tutorial-uko-satellite-next-step)


## Tutorials on Bring Your Own HSM
{: #sitemap_tutorials_on_bring_your_own_hsm}


[Managing your keys with BYOHSM in IBM Cloud Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm)

* [Objectives](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-objectives)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-prerequisites)

* [Task flow](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-steps)

* [Purchase and set up your on-premises HSMs](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-step1)

* [Configure and deploy your HSMs to work with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-step2)

* [Contact IBM to get the required information](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-step3)

* [Provision a Hyper Protect Crypto Services instance with BYOHSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-step4)

* [Use your Hyper Protect Crypto Services instance with BYOHSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-step5)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tutorial-byohsm&format=markdown#tutorial-byohsm-next)


## Provisioning service instances
{: #sitemap_provisioning_service_instances}


[Provisioning service instances](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&format=markdown#provision)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&format=markdown#provision-prerequisites)

* [Provisioning an instance of Hyper Protect Crypto Services Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&format=markdown#provision-standard)

* [Provisioning an instance of Hyper Protect Crypto Services with Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&format=markdown#provision-uko)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&format=markdown#provision-next)


## Initializing service instances
{: #sitemap_initializing_service_instances}


[Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-prerequisite&format=markdown#initialize-hsm-prerequisite)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-prerequisite&format=markdown#initialize-hsm-prerequisite-whats-next)


### Initializing service instances using smart cards and the Management Utilities
{: #sitemap_initializing_service_instances_using_smart_cards_and_the_management_utilities}


[Setting up smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-prepare-management-utilities&format=markdown#prepare-management-utilities)

* [Step 1: Order smart cards and smart card readers](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-prepare-management-utilities&format=markdown#order-smart-card-and-reader)

* [Step 2: Install the smart card reader driver on your local workstation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-prepare-management-utilities&format=markdown#install-smart-card-reader-driver)

* [Step 3: Install the Management Utilities on your local workstation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-prepare-management-utilities&format=markdown#install-management-utility-application)

* [Step 4: Configure smart cards with the Smart Card Utility Program](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-prepare-management-utilities&format=markdown#configure-smart-card-utility)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-prepare-management-utilities&format=markdown#prepare-management-utilities-next)

[Initializing service instances with smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-management-utilities&format=markdown#initialize-hsm-management-utilities)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-management-utilities&format=markdown#initialize-hsm-management-utilities-prerequisites)

* [Loading the master key from the smart cards](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-management-utilities&format=markdown#load-master-key-management-utilities)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-management-utilities&format=markdown#initialize-crypto-utilities-management-utilities-next)

[Initializing service instances using recovery crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-recovery-crypto-unit&format=markdown#initialize-hsm-recovery-crypto-unit)

* [Initializing service instances](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-recovery-crypto-unit&format=markdown#initialize-hsm-recovery-crypto-unit-steps)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm-recovery-crypto-unit&format=markdown#initialize-hsm-recovery-crypto-unit-whats-next)

[Initializing service instances using key part files](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#initialize-hsm)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#initialize-hsm-cli-prerequisite)

* [Selecting target crypto units for service initialization](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#identify_crypto_units)

* [Loading master keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#load-master-keys)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#initialize-crypto-cli-next)

[Using a signing service to manage signature keys for instance initialization](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-signing-service-signature-key&format=markdown#signing-service-signature-key)

* [Signing service prerequisites](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-signing-service-signature-key&format=markdown#signing-service-requirements)

* [Configuring the TKE CLI plug-in to use the signing service](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-signing-service-signature-key&format=markdown#configure-tke-cli-for-signing-service)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-signing-service-signature-key&format=markdown#signing-service-whats-next)


## Retrieving an access token
{: #sitemap_retrieving_an_access_token}


[Retrieving an access token](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-access-token&format=markdown#retrieve-access-token)

* [Retrieving an access token with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-access-token&interface=cli&format=markdown#retrieve-token-cli)

* [Retrieving an access token with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-access-token&interface=api&format=markdown#retrieve-token-api)


## Retrieving your instance ID
{: #sitemap_retrieving_your_instance_id}


[Retrieving your instance ID](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&format=markdown#retrieve-instance-ID)

* [Viewing your instance ID with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&interface=ui&format=markdown#view-instance-ID)

* [Retrieving an instance ID with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&interface=cli&format=markdown#retrieve-instance-ID-cli)

* [Retrieving an instance ID with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&interface=api&format=markdown#retrieve-instance-ID-api)


## Setting up API calls
{: #sitemap_setting_up_api_calls}


[Managing your keys with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-kms-api&format=markdown#set-up-kms-api)

* [Retrieving your IBM Cloud credentials](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-kms-api&format=markdown#retrieve-kms-credentials)

* [Forming your key management service API request](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-kms-api&format=markdown#form-kms-api-request)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-kms-api&format=markdown#set-up-kms-api-next-steps)

[Setting up Unified Key Orchestrator API calls - Unified Key Orchestrator Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-uko-api&format=markdown#set-up-uko-api)

* [Retrieving your IBM Cloud credentials](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-uko-api&format=markdown#retrieve-uko-credentials)

* [Forming your Unified Key Orchestrator API request](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-uko-api&format=markdown#form-uko-api-request)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-uko-api&format=markdown#set-up-uko-api-next-steps)

[Performing cryptographic operations with the PKCS #11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#set-up-pkcs-api)

* [Prerequisites](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#prerequisite-pkcs-api)

* [Step 1: Set up the PKCS #11 library](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#step1-setup-pkcs-library)

* [Step 2: (Optional) Verify the integrity and authenticity of the PKCS #11 library](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#step2-verify-pkcs-library)

* [Step 3: Set up the PKCS #11 configuration file](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#step3-setup-configuration-file)

* [Step 4: Use the PKCS #11 library to make PKCS #11 API calls](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#step4-use-pkcs-library)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-pkcs-api&format=markdown#set-up-pkcs-api-next-steps)

[Performing cryptographic operations with the GREP11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-grep11-api&format=markdown#set-up-grep11-api)

* [Retrieving your IBM Cloud credentials](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-grep11-api&format=markdown#retrieve-grep11-credentials)

* [Generating a GREP11 API request](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-grep11-api&format=markdown#form-grep11-api-request)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-grep11-api&format=markdown#set-up-grep11-api-next-steps)

[Enabling the second layer of authentication for EP11 connections - Standard Plan only](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11)

* [Security and availability best practices for enabling mutual TLS authentication](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-security-best-practices)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-prerequisites)

* [Step 1: Configure the administrator signature key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-step1-signature)

* [Step 2: Set up the client CA certificate for authentication](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-step2-certificate)

* [Step 3: Establish mutual TLS connections for EP11 applications](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-step3-enable-tls)

* [(Optional) Disabling mutual TLS connections](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-disable-tls)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-authentication-ep11&format=markdown#enable-authentication-ep11-whats-next)


## Performing key management operations with the CLI - Standard Plan only
{: #sitemap_performing_key_management_operations_with_the_cli_standard_plan_only}


[Performing key management operations with the CLI - Standard Plan only](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-cli&format=markdown#set-up-cli)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-up-cli&format=markdown#cli-next-steps)


## Setting up Terraform
{: #sitemap_setting_up_terraform}


[Setting up Terraform for Hyper Protect Crypto Services Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-terraform-setup-for-hpcs&format=markdown#terraform-setup-for-hpcs)

* [Example: Provisioning and initializing service instances by using Terraform](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-terraform-setup-for-hpcs&format=markdown#terraform-provision-initialize-instance-hpcs)

* [What's next?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-terraform-setup-for-hpcs&format=markdown#terraform-setup-hpcs-next)

[Setting up Terraform for Hyper Protect Crypto Services with Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-terraform-setup-for-hpcs&format=markdown#uko-terraform-setup-for-hpcs)

* [Example: Provisioning and initializing service instances by using Terraform](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-terraform-setup-for-hpcs&format=markdown#uko-terraform-provision-initialize-instance-hpcs)

* [What's next?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-terraform-setup-for-hpcs&format=markdown#uko-terraform-setup-hpcs-next)


## Setting up BYOHSM
{: #sitemap_setting_up_byohsm}


[Setting up BYOHSM](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-hsm-for-byohsm)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-byohsm-prerequisites)

* [Creating partitions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-byohsm-partition)

* [Creating keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-byohsm-key)

* [Network connectivity best practice](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-byohsm-network-connection)

* [Preparing information for HSM connection](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-byohsm-prepare-info)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-deploy-hsm-for-byohsm&format=markdown#deploy-hsm-next)


## Managing keys, keystores, and KMIP adapters - Standard Plan
{: #sitemap_managing_keys_keystores_and_kmip_adapters_standard_plan}



### Managing instance policies - Standard Plan
{: #sitemap_managing_instance_policies_standard_plan}


[Managing the network access policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-network-access-policies&format=markdown#managing-network-access-policies)

* [Updating the network access policy for your Hyper Protect Crypto Services instance with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-network-access-policies&interface=ui&format=markdown#update-network-access-policy-ui)

* [Updating the network access policy for your Hyper Protect Crypto Services instance with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-network-access-policies&interface=api&format=markdown#update-network-access-policy-api)

* [Updating the network access policy for your Hyper Protect Crypto Services instance with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-network-access-policies&interface=cli&format=markdown#update-network-access-policy-cli)

* [Disabling the network access policy for your Hyper Protect Crypto Services instance with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-network-access-policies&interface=api&format=markdown#disable-network-access-policy-api)

[Managing dual authorization of your service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-dual-auth&format=markdown#manage-dual-auth)

* [Understanding dual authorization of your service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-dual-auth&format=markdown#understand-daul-auth-policy)

* [Enabling dual authorization for your service instance with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-dual-auth&interface=ui&format=markdown#enable-dual-auth-instance-policy-ui)

* [Enabling dual authorization for your service instance with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-dual-auth&interface=api&format=markdown#enable-dual-auth-instance-policy-api)

* [Disabling dual authorization for your service instance with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-dual-auth&interface=ui&format=markdown#disable-dual-auth-instance-policy-ui)

* [Disabling dual authorization for your service instance with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-dual-auth&interface=api&format=markdown#disable-dual-auth-instance-policy-api)

[Managing the key create and import access policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-keyCreateImportAccess&format=markdown#manage-keyCreateImportAccess)

* [Understanding the key create and import access settings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-keyCreateImportAccess&format=markdown#understand-keyCreateImportAccess-instance-policy)

* [Enabling or updating the key create and import access policy for your service instance with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-keyCreateImportAccess&interface=ui&format=markdown#enable-keyCreateImportAccess-policy-console)

* [Enabling and updating the key create and import access policy for your service instance with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-keyCreateImportAccess&interface=api&format=markdown#enable-keyCreateImportAccess-policy-api)

* [Disabling the key create and import access policy for your service instance with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-keyCreateImportAccess&interface=api&format=markdown#disable-key-create-import-policy-api)


### Managing key management service keys - Standard Plan
{: #sitemap_managing_key_management_service_keys_standard_plan}


[Creating root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-root-keys&format=markdown#create-root-keys)

* [Creating root keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-root-keys&interface=ui&format=markdown#root-key-gui)

* [Creating root keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-root-keys&interface=api&format=markdown#root-key-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-root-keys&interface=api&format=markdown#root-key-next)

[Creating standard keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-standard-keys&format=markdown#create-standard-keys)

* [Creating standard keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-standard-keys&interface=ui&format=markdown#standard-key-gui)

* [Creating standard keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-standard-keys&interface=api&format=markdown#create-standard-key-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-standard-keys&interface=api&format=markdown#standard-key-next)

[Managing key rings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&format=markdown#managing-key-rings)

* [Creating key rings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&format=markdown#create-key-ring)

* [Transferring a key to a different key ring](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&format=markdown#transfer-key-key-ring)

* [Granting access to a key ring](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&interface=ui&format=markdown#grant-access-key-ring)

* [Listing key rings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&interface=ui&format=markdown#list-key-ring)

* [Deleting key rings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&interface=ui&format=markdown#delete-key-ring)

[Managing key aliases](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-key-alias&format=markdown#manage-key-alias)

* [Creating key aliases](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-key-alias&format=markdown#create-key-alias)

* [Deleting key aliases](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-key-alias&format=markdown#delete-key-alias)

* [APIs that use key alias](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-key-alias&interface=api&format=markdown#key-alias-apis)

[Importing root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&format=markdown#import-root-keys)

* [Importing root keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&interface=ui&format=markdown#import-root-key-gui)

* [Importing root keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&interface=api&format=markdown#import-root-key-api)

* [Importing root keys with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&interface=cli&format=markdown#import-root-key-cli)

* [Base64 encoding your key material](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&interface=cli&format=markdown#encode-key-material-root-key)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&interface=cli&format=markdown#import-root-key-next)

[Importing standard keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-standard-keys&format=markdown#import-standard-keys)

* [Importing standard keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-standard-keys&interface=ui&format=markdown#import-standard-key-gui)

* [Importing standard keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-standard-keys&interface=api&format=markdown#import-standard-key-api)

* [Importing standard keys with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-standard-keys&interface=cli&format=markdown#import-standard-key-cli)

* [Base64 encoding your key material](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-standard-keys&interface=cli&format=markdown#encode-key-material-standard-key)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-standard-keys&interface=cli&format=markdown#import-standard-key-next)

[Creating import tokens](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&format=markdown#create-import-tokens)

* [Creating an import token with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&interface=api&format=markdown#create-import-token-api)

* [Creating an import token with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&interface=cli&format=markdown#create-import-token-cli)

* [Retrieving an import token with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&interface=api&format=markdown#retrieve-import-token-api)

* [Retrieving an import token with the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&interface=cli&format=markdown#retrieve-import-token-cli)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&interface=cli&format=markdown#create-import-token-next-steps)

[Viewing a list of root keys or standard keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-keys&format=markdown#view-keys)

* [Viewing root keys or standard keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-keys&interface=ui&format=markdown#view-key-gui)

* [Viewing root keys or standard keys with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-keys&interface=api&format=markdown#view-key-api)

[Viewing details about a root key or a standard key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-details&format=markdown#view-key-details)

* [Viewing key details with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-details&interface=ui&format=markdown#view-key-details-ui)

* [Viewing key details with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-details&interface=api&format=markdown#view-key-details-api)

[Retrieving a root key or a standard key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-key&format=markdown#retrieve-key)

* [Retrieving a key with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-key&format=markdown#get-key-api)

[Wrapping data encryption keys with root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-wrap-keys&format=markdown#wrap-keys)

* [Wrapping keys by using the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-wrap-keys&format=markdown#wrap-keys-api)

[Unwrapping data encryption keys with root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-unwrap-keys&format=markdown#unwrap-keys)

* [Unwrapping keys by using the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-unwrap-keys&format=markdown#unwrap-key-api)

* [Decoding your key material](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-unwrap-keys&format=markdown#how-to-decode-key-material)

[Rewrapping data encryption keys with root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rewrap-keys&format=markdown#rewrap-keys)

* [Rewrapping keys by using the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rewrap-keys&format=markdown#rewrap-key-api)

[Rotating root keys based on the rotation policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-rotation-policy&format=markdown#set-rotation-policy)

* [Managing rotation policies in the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-rotation-policy&interface=ui&format=markdown#manage-policies-gui)

* [Managing rotation policies with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-rotation-policy&interface=api&format=markdown#manage-rotation-policies-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-rotation-policy&interface=api&format=markdown#set-rotation-policy-next)

[Rotating root keys manually](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-keys&format=markdown#rotate-keys)

* [Rotating root keys in the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-keys&interface=ui&format=markdown#rotate-root-key-gui)

* [Rotating root keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-keys&interface=api&format=markdown#rotate-root-key-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-keys&interface=api&format=markdown#rotate-key-next)

[Viewing root key versions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-versions&format=markdown#view-key-versions)

* [Viewing root key versions with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-versions&format=markdown#view-key-versions-api)

[Disabling root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disable-keys&format=markdown#disable-keys)

* [Disabling and enabling root keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disable-keys&interface=ui&format=markdown#disable-enable-ui)

* [Disabling and enabling root keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disable-keys&interface=api&format=markdown#disable-enable-api)

[About deleting and purging keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-purge-keys&format=markdown#delete-purge-keys)

* [Considerations before you delete and purge a key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-purge-keys&format=markdown#delete-purge-keys-considerations)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-purge-keys&format=markdown#delete-purge-keys-next)

[Deleting keys by using a single authorization](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-keys&format=markdown#delete-keys)

* [Deleting keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-keys&interface=ui&format=markdown#delete-keys-gui)

* [Deleting keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-keys&interface=api&format=markdown#delete-keys-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-keys&interface=api&format=markdown#delete-key-next)

[Deleting keys by using dual authorization](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-dual-auth-keys&format=markdown#delete-dual-auth-keys)

* [Considerations for deleting a key using dual authorization](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-dual-auth-keys&format=markdown#dual-auth-deletion-considerations)

* [Authorize deletion for a key with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-dual-auth-keys&interface=ui&format=markdown#set-key-deletion-console)

* [Authorize deletion for a key with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-dual-auth-keys&interface=api&format=markdown#set-key-deletion-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-dual-auth-keys&interface=api&format=markdown#delete-daul-auth-keys-next)

[Setting dual authorization policies for keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-dual-auth-key-policy&format=markdown#set-dual-auth-key-policy)

* [Managing dual authorization policies with the key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-set-dual-auth-key-policy&format=markdown#manage-dual-auth-key-policies-api)

[Purging keys manually](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-purge-keys&format=markdown#purge-keys)

* [Purging keys in the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-purge-keys&interface=ui&format=markdown#purge-keys-gui)

* [Purging keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-purge-keys&interface=api&format=markdown#purge-keys-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-purge-keys&interface=api&format=markdown#purge-keys-next)

[Restoring keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-keys&format=markdown#restore-keys)

* [How do I know whether a key can be restored?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-keys&format=markdown#restore-keys-eligibility)

* [Restoring a deleted key with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-keys&interface=ui&format=markdown#restore-keys-ui)

* [Restoring a deleted key with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-keys&interface=api&format=markdown#restore-keys-api)

[Viewing associations between root keys and encrypted IBM Cloud resources](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-protected-resources&format=markdown#view-protected-resources)

* [Viewing protected resources with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-protected-resources&interface=ui&format=markdown#view-protected-resources-gui)

* [Viewing protected resources with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-protected-resources&interface=api&format=markdown#view-protected-resources-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-protected-resources&interface=api&format=markdown#view-protected-resources-next-steps)

[Synchronizing associated resources](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-sync-associated-resources&format=markdown#sync-associated-resources)

* [Syncing associated resources with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-sync-associated-resources&interface=ui&format=markdown#sync-associated-resources-ui)

* [Syncing associated resources with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-sync-associated-resources&interface=api&format=markdown#sync-associated-resources-api)


### Managing EP11 keys, keystores, and certificates  - Standard Plan
{: #sitemap_managing_ep11_keys_keystores_and_certificates_standard_plan}


[Managing EP11 keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-keystores-ui&format=markdown#manage-ep11-keystores-ui)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-keystores-ui&format=markdown#manage-ep11-keystores-ui-before)

* [Viewing EP11 keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-keystores-ui&format=markdown#view-ep11-keystore-ui)

* [Creating EP11 keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-keystores-ui&format=markdown#create-ep11-keystore-ui)

* [Deleting EP11 keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-keystores-ui&format=markdown#delete-ep11-keystore-ui)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-keystores-ui&format=markdown#manage-ep11-keystore-ui-next)

[Managing EP11 keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-key-ui&format=markdown#manage-ep11-key-ui)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-key-ui&format=markdown#manage-ep11-key-ui-before)

* [Viewing EP11 keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-key-ui&format=markdown#view-ep11-key-ui)

* [Creating EP11 keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-key-ui&format=markdown#create-ep11-key-ui)

* [Deleting EP11 keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-key-ui&format=markdown#delete-ep11-key-ui)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-key-ui&format=markdown#manage-ep11-key-ui-next)

[Managing EP11 certificates with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-certificate-ui&format=markdown#manage-ep11-certificate-ui)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-certificate-ui&format=markdown#manage-ep11-certificate-ui-before)

* [Viewing EP11 certificates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-certificate-ui&format=markdown#view-ep11-certificate-ui)

* [Downloading EP11 certificates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-certificate-ui&format=markdown#download-ep11-certificate-ui)

* [Deleting EP11 certificates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-certificate-ui&format=markdown#delete-ep11-certificate-ui)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-ep11-certificate-ui&format=markdown#manage-ep11-certificate-ui-next)


## Managing keys and keystores - Unified Key Orchestrator Plan
{: #sitemap_managing_keys_and_keystores_unified_key_orchestrator_plan}



### Managing vaults - Unified Key Orchestrator Plan
{: #sitemap_managing_vaults_unified_key_orchestrator_plan}


[Creating vaults](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-vaults&format=markdown#create-vaults)

* [Creating vaults with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-vaults&interface=ui&format=markdown#create-vaults-ui)

* [Creating vaults through the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-vaults&interface=api&format=markdown#create-vaults-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-vaults&interface=api&format=markdown#create-vaults-next)

[Editing vault details](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-vaults&format=markdown#edit-vaults)

* [Editing vault details with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-vaults&interface=ui&format=markdown#edit-vaults-ui)

* [Editing vault details with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-vaults&interface=api&format=markdown#edit-vaults-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-vaults&interface=api&format=markdown#edit-vaults-next)

[Deleting vaults](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-vaults&format=markdown#delete-vaults)

* [Deleting vaults with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-vaults&interface=ui&format=markdown#delete-vaults-ui)

* [Deleting vaults with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-vaults&interface=api&format=markdown#delete-vaults-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-vaults&interface=api&format=markdown#delete-vaults-next)


### Managing key templates - Unified Key Orchestrator Plan
{: #sitemap_managing_key_templates_unified_key_orchestrator_plan}


[Creating key templates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&format=markdown#create-template)

* [Creating key templates from scratch with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&interface=ui&format=markdown#create-template-ui)

* [Creating key templates from scratch through the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&interface=api&format=markdown#create-template-api)

* [Creating a copy of an existing key template with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&interface=ui&format=markdown#copy-template-ui)

* [Creating key templates from an existing key template through the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&interface=api&format=markdown#copy-template-api)

* [Defining key naming schemes](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&interface=ui&format=markdown#define-naming-scheme)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-template&interface=ui&format=markdown#create-template-next)

[Viewing a list of key templates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-template&format=markdown#view-key-template)

* [Viewing a list of key templates with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-template&interface=ui&format=markdown#view-key-template-ui)

* [Viewing a list of key templates with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-template&interface=api&format=markdown#view-key-template-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-template&interface=api&format=markdown#view-key-template-next)

[Editing key template details](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-template&format=markdown#edit-template)

* [Editing key templates with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-template&interface=ui&format=markdown#edit-key-template-ui)

* [Editing key templates with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-template&interface=api&format=markdown#edit-key-template-api)

* [Editing keystores for key templates with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-template&interface=api&format=markdown#assign-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-template&interface=api&format=markdown#edit-key-template-next)

[Archiving and unarchiving key templates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-archive-template&format=markdown#archive-template)

* [Archiving key templates with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-archive-template&interface=ui&format=markdown#archive-key-template-ui)

* [Archiving key templates with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-archive-template&interface=api&format=markdown#archive-key-template-api)

* [Unarchiving key templates with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-archive-template&interface=ui&format=markdown#unarchive-key-template-ui)

* [Unarchiving key templates with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-archive-template&interface=api&format=markdown#unarchive-key-template-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-archive-template&interface=api&format=markdown#archive-key-template-next)

[Deleting key templates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-template&format=markdown#delete-template)

* [Deleting key templates with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-template&interface=ui&format=markdown#delete-key-template-ui)

* [Deleting key templates with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-template&interface=api&format=markdown#delete-key-template-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-template&interface=api&format=markdown#delete-key-template-next)


### Managing keys - Unified Key Orchestrator Plan
{: #sitemap_managing_keys_unified_key_orchestrator_plan}


[Creating managed keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-managed-keys&format=markdown#create-managed-keys)

* [Creating managed keys with a key template in the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-managed-keys&interface=ui&format=markdown#create-managed-keys-template-ui)

* [Creating managed keys with a key template through the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-managed-keys&interface=api&format=markdown#create-managed-keys-template-api)

* [Creating managed keys with custom properties in the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-managed-keys&interface=ui&format=markdown#create-managed-keys-ui)

* [Creating managed keys with custom properties through the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-managed-keys&interface=api&format=markdown#create-managed-keys-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-managed-keys&interface=api&format=markdown#create-managed-keys-next)

[Viewing a list of managed keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-list&format=markdown#view-key-list)

* [Viewing a list of managed keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-list&interface=ui&format=markdown#view-key-list-ui)

* [Viewing a list of keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-list&interface=api&format=markdown#view-key-list-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-key-list&interface=api&format=markdown#view-key-list-next)

[Filtering and searching managed keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-search-key-list&format=markdown#search-key-list)

* [Filtering managed keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-search-key-list&interface=ui&format=markdown#filter-key-list-ui)

* [ Searching for keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-search-key-list&interface=ui&format=markdown#search-key-list-ui)

* [Searching keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-search-key-list&interface=api&format=markdown#search-key-list-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-search-key-list&interface=api&format=markdown#search-key-list-next)

[Editing managed key details](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-kms-keys&format=markdown#edit-kms-keys)

* [Editing managed key details with the  UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-kms-keys&interface=ui&format=markdown#edit-kms-keys-ui)

* [Editing key details with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-kms-keys&interface=api&format=markdown#edit-kms-keys-api)

* [Editing keystores for keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-kms-keys&interface=api&format=markdown#assign-key-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-kms-keys&interface=api&format=markdown#edit-kms-keys-next)

[Rotating managed keys manually](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-rotate-keys&format=markdown#uko-rotate-keys)

* [Rotating managed keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-rotate-keys&interface=ui&format=markdown#uko-rotate-managed-key-gui)

* [Rotating managed keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-rotate-keys&interface=api&format=markdown#uko-rotate-managed-key-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-rotate-keys&interface=api&format=markdown#uko-rotate-keys-next)

[Syncing keys in keystores with managed keys manually](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-sync-keys&format=markdown#uko-sync-keys)

* [Syncing keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-sync-keys&interface=ui&format=markdown#uko-sync-managed-key-gui)

* [Syncing with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-sync-keys&interface=api&format=markdown#uko-sync-managed-key-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-sync-keys&interface=api&format=markdown#uko-sync-keys-next)

[Realigning managed keys with key templates](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-align-key&format=markdown#align-key)

* [Realigning managed keys with key templates through the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-align-key&interface=ui&format=markdown#align-key-ui)

* [Realigning keys with key templates through the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-align-key&interface=api&format=markdown#align-key-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-align-key&interface=api&format=markdown#align-key-next)

[Viewing managed key versions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-view-key-versions&format=markdown#uko-view-key-versions)

* [Viewing manage key versions with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-view-key-versions&interface=ui&format=markdown#uko-view-key-versions-gui)

* [Viewing managed key versions with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-view-key-versions&interface=api&format=markdown#uko-view-key-versions-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-view-key-versions&interface=api&format=markdown#uko-view-key-versions-next)

[Deleting managed keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-managed-keys&format=markdown#delete-managed-keys)

* [Deleting managed keys with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-managed-keys&interface=ui&format=markdown#delete-managed-keys-ui)

* [Deleting managed keys with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-managed-keys&interface=api&format=markdown#delete-managed-keys-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-managed-keys&interface=api&format=markdown#delete-managed-keys-next)


### Managing keystores - Unified Key Orchestrator Plan
{: #sitemap_managing_keystores_unified_key_orchestrator_plan}


[Creating internal KMS keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-internal-keystores&format=markdown#create-internal-keystores)

* [Creating internal KMS keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-internal-keystores&interface=ui&format=markdown#create-internal-keystores-ui)

* [Creating internal KMS keystores with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-internal-keystores&interface=api&format=markdown#create-internal-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-internal-keystores&interface=api&format=markdown#create-internal-keystores-next)

[Connecting to external keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-external-keystores&format=markdown#connect-external-keystores)

* [Setting up required user access in external keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-external-keystores&format=markdown#connect-external-keystores-access)

* [Connecting to external keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-external-keystores&interface=ui&format=markdown#connect-external-keystores-ui)

* [Connecting to external keystores with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-external-keystores&interface=api&format=markdown#connect-external-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-external-keystores&interface=api&format=markdown#connect-external-keystores-next)

[Editing internal keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-internal-keystores&format=markdown#edit-internal-keystores)

* [Editing internal keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-internal-keystores&interface=ui&format=markdown#edit-internal-keystores-ui)

* [Editing internal keystores with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-internal-keystores&interface=api&format=markdown#edit-internal-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-internal-keystores&interface=api&format=markdown#edit-internal-keystores-next)

[Editing connection to external keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-external-keystore-connection&format=markdown#edit-external-keystore-connection)

* [Editing connection to external keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-external-keystore-connection&interface=ui&format=markdown#edit-external-keystore-connection-ui)

* [Editing connection to external keystores with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-external-keystore-connection&interface=api&format=markdown#edit-external-keystore-connection-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-edit-external-keystore-connection&interface=api&format=markdown#edit-external-keystore-connection-next)

[Deleting internal keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-internal-keystores&format=markdown#delete-internal-keystores)

* [Deleting internal keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-internal-keystores&interface=ui&format=markdown#delete-internal-keystores-ui)

* [Deleting internal keystores with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-internal-keystores&interface=api&format=markdown#delete-internal-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-internal-keystores&interface=api&format=markdown#delete-internal-keystores-next)

[Disconnecting from external keystores](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disconnect-external-keystores&format=markdown#disconnect-external-keystores)

* [Disconnecting from external keystores with the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disconnect-external-keystores&interface=ui&format=markdown#disconnect-external-keystores-ui)

* [Disconnecting from external keystores with the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disconnect-external-keystores&interface=api&format=markdown#disconnect-external-keystores-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-disconnect-external-keystores&interface=api&format=markdown#disconnect-external-keystores-next)

[Connecting to Azure Key Vault through private endpoint](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&format=markdown#connect-azure-key-vault-private-endpoint)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&interface=ui&format=markdown#prerequisite)

* [Step 1: Create a private endpoint in Azure portal](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&interface=ui&format=markdown#step1-create-private-endpoint-ui)

* [Step 2: Create and manage connector endpoint](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&interface=ui&format=markdown#step2-create-manage-endpoint-ui)

* [Step 3: Connect Azure Key Vault to the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&interface=ui&format=markdown#step3-connect-azure-key-vault-ui)

* [Connecting to Azure Key Vault with API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&interface=api&format=markdown#connect-azure-key-vault-api)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-connect-azure-key-vault-private-endpoint&interface=api&format=markdown#connect-azure-key-vault-private-endpoint-next)


## Managing master keys
{: #sitemap_managing_master_keys}


[Rotating master keys by using smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-smart-cards&format=markdown#rotate-master-key-smart-cards)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-smart-cards&format=markdown#rotate-master-key-smart-cards-prerequisites)

* [Rotating master keys using smart cards and the Management Utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-smart-cards&format=markdown#rotate-master-key-smart-cards-steps)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-smart-cards&format=markdown#rotate-master-key-smart-cards-next)

[Rotating master keys by using recovery crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-recovery-crypto-unit&format=markdown#rotate-master-key-cli-recovery-crypto-unit)

* [Rotating master keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-recovery-crypto-unit&format=markdown#rotate-master-key-cli-recovery-crypto-unit-steps)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-recovery-crypto-unit&format=markdown#rotate-master-key-cli-recovery-crypto-unit-next)

[Rotating master keys by using key part files](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-key-part&format=markdown#rotate-master-key-cli-key-part)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-key-part&format=markdown#rotate-master-key-cli-key-part-prerequisites)

* [Rotating master keys by using key part files](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-key-part&format=markdown#rotate-master-key-cli-key-part-steps)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-rotate-master-key-cli-key-part&format=markdown#rotate-master-key-cli-key-part-next)

[Recovering a master key from a recovery crypto unit](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-recover-master-key-recovery-crypto-unit&format=markdown#recover-master-key-recovery-crypto-unit)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-recover-master-key-recovery-crypto-unit&format=markdown#recover-master-key-prerequisites)

* [Recovering master keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-recover-master-key-recovery-crypto-unit&format=markdown#recover-master-key-step)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-recover-master-key-recovery-crypto-unit&format=markdown#recover-master-key-next)


## Enabling crypto mechanisms
{: #sitemap_enabling_crypto_mechanisms}


[Enabling crypto mechanisms](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-mechanisms&format=markdown#enable-mechanisms)

* [Enabling BIP32 deterministic wallets](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-mechanisms&format=markdown#enable-BIP32)

* [Enabling Edwards-curve Digital Signature Algorithm](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-mechanisms&format=markdown#enable-EdDSA)

* [Enabling the Schnorr algorithm](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-mechanisms&format=markdown#enable-schnorr)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-mechanisms&format=markdown#next-enable-mechanisms)


## Adding or removing crypto units
{: #sitemap_adding_or_removing_crypto_units}


[Adding or removing crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-add-remove-crypto-units&format=markdown#add-remove-crypto-units)

* [Adding crypto units to an existing service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-add-remove-crypto-units&format=markdown#add-crypto-units)

* [Removing crypto units from an existing service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-add-remove-crypto-units&format=markdown#remove-crypto-units)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-add-remove-crypto-units&format=markdown#add-remove-crypto-units-next)


## Enabling or adding failover crypto units after you provision a service instance
{: #sitemap_enabling_or_adding_failover_crypto_units_after_you_provision_a_service_instance}


[Enabling or adding failover crypto units after you provision a service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-add-failover&format=markdown#enable-add-failover)

* [Step 1: Add failover crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-add-failover&format=markdown#add-failover-cu)

* [Step 2: Raise a support ticket](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-add-failover&format=markdown#raise-support-ticket)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-enable-add-failover&format=markdown#enable-add-failover-next)


## Deleting service instances
{: #sitemap_deleting_service_instances}


[Deleting service instances](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#delete-instance)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#delete-instance-prerequisite)

* [Step 1: Delete keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#delete-all-key-step)

* [Step 2: Select the crypto units to be deleted](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#select-crypto-unit-step)

* [Step 3: Zeroize crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#zeroize-crypto-unit-step)

* [Step 4: Optional - Uninstall the Hyper Protect Crypto Services utilities](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#uninstall-utilities-step)

* [Step 5: Delete your service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-delete-instance&format=markdown#delete-instance-step)


## Restoring your data from another region
{: #sitemap_restoring_your_data_from_another_region}


[Restoring your data from another region](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-data&format=markdown#restore-data)

* [Restoring your data by using failover crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-data&format=markdown#restore-data-failover-crypto-units)

* [Restoring your data by opening an IBM support ticket](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-data&format=markdown#restore-data-open-support-ticket)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-restore-data&format=markdown#restore-data-next)


## Enhancing security - Standard Plan
{: #sitemap_enhancing_security_standard_plan}


[Managing user access](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#manage-access)

* [Roles and permissions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#roles)

* [Managing access to multiple instances](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#manage-multiple-instances)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#manage-access-next)

[Granting access to keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-keys&format=markdown#grant-access-keys)

* [Granting access to all keys in an instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-keys&format=markdown#grant-access-instance-level)

* [Granting access to a single key in an instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-keys&format=markdown#grant-access-key-level)

* [Granting access to key rings in an instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-keys&format=markdown#grant-access-key-ring-level)


### Granting users access to manage EP11 keystores and keys
{: #sitemap_granting_users_access_to_manage_ep11_keystores_and_keys}


[Granting users access to manage EP11 keystores and keys through UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-pkcs11-ui-access&format=markdown#grant-pkcs11-ui-access)

* [(Optional) Step 1: Create custom IAM roles](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-pkcs11-ui-access&format=markdown#step1-create-custom-roles-pkcs11-ui)

* [Step 2: Assign IAM roles to users](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-pkcs11-ui-access&format=markdown#step2-assign-iam-roles-pkcs-ui)

* [ What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-pkcs11-ui-access&format=markdown#pkcs11-ui-best-practices-next)

[Setting up PKCS #11 API user types](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-best-practice-pkcs11-access&format=markdown#best-practice-pkcs11-access)

* [ PKCS #11 user types](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-best-practice-pkcs11-access&format=markdown#pkcs11-user-types)

* [Step 1: Create custom IAM roles](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-best-practice-pkcs11-access&format=markdown#step1-create-custom-roles)

* [ Step 2: Create service IDs and API keys for the SO user, normal user, and anonymous user](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-best-practice-pkcs11-access&format=markdown#step2-create-service-id-api-key)

* [Step 3: Assign IAM roles to the service IDs](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-best-practice-pkcs11-access&format=markdown#step3-assign-iam-roles)

* [ What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-best-practice-pkcs11-access&format=markdown#pkcs11-best-practices-next)


### Privately connecting to Hyper Protect Crypto Services
{: #sitemap_privately_connecting_to_hyper_protect_crypto_services}


[Using virtual private endpoints for VPC to privately connect to Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-virtual-private-endpoints-for-vpc&format=markdown#virtual-private-endpoints-for-vpc)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-virtual-private-endpoints-for-vpc&format=markdown#virtual-private-endpoints-for-vpc-prereqs)

* [Setting up a VPE for Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-virtual-private-endpoints-for-vpc&format=markdown#virtual-private-endpoints-for-vpc-setup)

* [Using your VPE for Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-virtual-private-endpoints-for-vpc&format=markdown#use-vpe-for-hpcs)

[Using service endpoints to privately connect to Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#secure-connection)

* [Understanding the network access policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#understand-network-access-policies)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#private-endpoint-prereqs)

* [Step 1: Configure the private network of IBM Cloud on your virtual server](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#configure-network)

* [Step 2: Provision a service instance and select the network access](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#service-endpoint-private-endpoints)

* [Step 3:  Target the Hyper Protect Crypto Services private endpoint for the TKE CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#target-tke-private-endpoint)

* [Step 4: Initialize the service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#secure-connection-key-ceremony)

* [Step 5: Target the Hyper Protect Crypto Services private endpoint for key management service](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#target-internal-endpoint)

* [Step 6: Test your private network connection](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#Test-private-connection)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-secure-connection&format=markdown#secure-connection-next)

[Auditing events for Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#at-events)

* [Historical information regarding events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#historical-mapping-events)

* [Supported events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#at-supported-events)

* [Viewing events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#at-ui)

* [Analyzing successful events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#at-events-analyze)

* [Analyzing failed events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#at-events-analyze-failed)

* [Event severity](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-at-events&format=markdown#event-severity)

[Managing security and compliance with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-security-compliance&format=markdown#manage-security-compliance)

* [Governing Hyper Protect Crypto Services resource configuration with config rules](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-security-compliance&format=markdown#govern-crypto)


## Enhancing security - Unified Key Orchestrator Plan
{: #sitemap_enhancing_security_unified_key_orchestrator_plan}


[Managing user access](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&format=markdown#uko-manage-access)

* [Roles and permissions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&format=markdown#uko-roles)

* [Assigning access to Hyper Protect Crypto Services in the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&interface=ui&format=markdown#assign-access-console)

* [Assigning access to Hyper Protect Crypto Services in the CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&interface=cli&format=markdown#assign-access-cli)

* [Assigning access to Hyper Protect Crypto Services by using the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&interface=api&format=markdown#assign-access-api)

* [Assigning access to Hyper Protect Crypto Services by using Terraform](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&interface=terraform&format=markdown#assign-access-terraform)

* [Managing access to multiple instances](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&interface=terraform&format=markdown#uko-manage-multiple-instances)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-manage-access&interface=terraform&format=markdown#uko-manage-access-next)

[Granting access to vaults](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-vaults&format=markdown#grant-access-vaults)

* [Step 1. Retrieve the vault ID](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-vaults&format=markdown#access-vault-retrieve-ID)

* [Step 2. Grant access to vaults from the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-vaults&format=markdown#grant-access-vault-console)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grant-access-vaults&format=markdown#grant-access-vaults-next)

[Setting up custom roles for Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-role-best-practices&format=markdown#uko-role-best-practices)

* [Step 1: Create custom IAM roles](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-role-best-practices&format=markdown#step1-create-custom-roles-uko)

* [Step 2: Assign IAM roles to users](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-role-best-practices&format=markdown#step2-assign-iam-roles-uko)

* [ What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-role-best-practices&format=markdown#uko-role-best-practices-next)

[Auditing events for Hyper Protect Crypto Services with Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-at-events&format=markdown#uko-at-events)

* [Supported events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-at-events&format=markdown#uko-at-supported-events)

* [Viewing events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-at-events&format=markdown#uko-at-ui)

* [Analyzing successful events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-at-events&format=markdown#uko-at-events-analyze)

* [Analyzing failed events](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-at-events&format=markdown#uko-at-events-analyze-failed)

* [Event severity](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-at-events&format=markdown#uko-event-severity)


## Logging and monitoring
{: #sitemap_logging_and_monitoring}


[Managing metrics](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-monitoring-metrics&format=markdown#manage-monitoring-metrics)

* [Managing metrics settings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-monitoring-metrics&format=markdown#manage-metrics-policy)

* [What's next](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-monitoring-metrics&format=markdown#monitor-metrics-next-steps)

[Monitoring operational metrics](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#operational-metrics)

* [What metrics are available for Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#hpcs-metrics-available)

* [Before you begin](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#operational-metrics-considerations)

* [Connecting Monitoring with Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#connect-monitoring-hpcs)

* [Hyper Protect Crypto Services Metrics Details](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#hpcs-metrics)

* [Latency](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#latency)

* [Attributes for Segmentation](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#attributes-for-segmentation)

* [Default Dashboards](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#default-dashboards)

* [Setting Alerts](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-operational-metrics&format=markdown#set-monitor-alerts)


## API reference
{: #sitemap_api_reference}



### Key management service API
{: #sitemap_key_management_service_api}


[Hyper Protect Crypto Services key management service API change log](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-kms-api-change-log&format=markdown#kms-api-change-log)

* [API versioning](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-kms-api-change-log&format=markdown#kms-api-versioning)

* [February 2024](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-kms-api-change-log&format=markdown#kms-api-feb-2024)

* [February 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-kms-api-change-log&format=markdown#kms-api-feb-2023)

* [January 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-kms-api-change-log&format=markdown#kms-api-jan-2022)

* [April 2021](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-kms-api-change-log&format=markdown#kms-api-april-2021)


### Unified Key Orchestrator API
{: #sitemap_unified_key_orchestrator_api}


[Hyper Protect Crypto Services Unified Key Orchestrator API change log](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-change-log)

* [API versioning](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-versioning)

* [August 2023](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-aug-2023)

* [December 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-december-2022)

* [October 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-october-2022)

* [July 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-july-2022)

* [June 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-june-2022)

* [March 2022](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-uko-api-change-log&format=markdown#uko-api-march-2022)

[Cryptographic operations: PKCS #11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs11-api-ref)

* [Installing and configuring PKCS #11 library](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#setup-pkcs11-library)

* [Error handling](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs11-error-handling)

* [Verifying that keys are protected by crypto units](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs11-key-verify)

* [PKCS #11 function list](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs11_function_list)

* [Supported mechanisms](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs-mechanism-list)

* [Supported attributes and key types](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs-attribute-list)

* [Supported curves](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#supported-pkcs11-curve-name)

* [Standard PKCS #11 API reference](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-pkcs11-api-ref&format=markdown#pkcs11-standard-api-ref)

[Cryptographic operations: GREP11 API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-api-ref)

* [Accessing the API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#access-grep11-functions)

* [Error handling](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-error-handling)

* [GREP11 function list](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11_function_list)

* [Supported mechanisms](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-mechanism-list)

* [Supported attributes and key types](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-attribute-list)

* [Supported curves](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#supported-grep11-curve-name)

* [Performing cryptographic operations with GREP11 functions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-functions)

* [Retrieving supported crypto algorithms](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-retrieve-mechanisms)

* [Generating and deriving keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-generate-keys)

* [Protecting keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-manage-keys)

* [Retrieving and modifying attributes for keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-attribute-value)

* [Generating random data](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-generate-random-data)

* [Encrypting and decrypting data](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-encrypt-decrypt-data)

* [Signing and verifying data](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-sign-verify-data)

* [Protecting data integrity through message digests](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#grep11-operation-digest-data)

* [Code examples](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-grep11-api-ref&format=markdown#code-example)


## CLI reference
{: #sitemap_cli_reference}


[Hyper Protect Crypto Services CLI change log](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-cli-change-log&format=markdown#cli-change-log)

* [IBM Cloud TKE CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-cli-change-log&format=markdown#tke-cli-change-log)

* [IBM Cloud Hyper Protect Crypto Services certificate manager CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-cli-change-log&format=markdown#cert-manager-cli-change-log)

* [IBM Cloud Hyper Protect Crypto Services Unified Key Orchestrator CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-cli-change-log&format=markdown#uko-cli-change-log)

[IBM Cloud Hyper Protect Crypto Services CLI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-hpcs-cli-plugin&format=markdown#hpcs-cli-plugin)

* [Hyper Protect Crypto Services key management CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-hpcs-cli-plugin&format=markdown#kp-cli-plugin)

* [Hyper Protect Crypto Services Trusted Key Entry CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-hpcs-cli-plugin&format=markdown#tke-cli-plugin)

* [Hyper Protect Crypto Services certificate manager CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-hpcs-cli-plugin&format=markdown#cert-manager-cli-plugin)

* [Hyper Protect Crypto Services Unified Key Orchestrator CLI plug-in](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-hpcs-cli-plugin&format=markdown#uko-cli-plugin)


## Terraform reference
{: #sitemap_terraform_reference}


[Provisioning and initializing service instances with Terraform](https://registry.terraform.io/providers/IBM-Cloud/ibm/latest/docs/resources/hpcs){: external}

[Managing keys with Terraform - Key management service](https://registry.terraform.io/providers/IBM-Cloud/ibm/latest/docs/resources/kms_key){: external}

[Managing keys with Terraform - Unified Key Orchestrator](https://registry.terraform.io/providers/IBM-Cloud/ibm/latest/docs/resources/hpcs_managed_key){: external}


## Regions and locations
{: #sitemap_regions_and_locations}


[Regions and locations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-regions&format=markdown#regions)

* [Available regions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-regions&format=markdown#available-regions)

* [Connectivity options](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-regions&format=markdown#connectivity-options)

* [Service endpoints](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-regions&format=markdown#service-endpoints)


## Hyper Protect Crypto Services cloud TKE procedures
{: #sitemap__cloud_tke_procedures}


[Hyper Protect Crypto Services cloud TKE procedures](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-tke-procedures&format=markdown#tke-procedures)


## Security considerations for initializing a service instance
{: #sitemap_security_considerations_for_initializing_a_service_instance}


[Security considerations for initializing a service instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialization-security-policy&format=markdown#initialization-security-policy)

* [Considerations for storing signature keys and master key parts](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialization-security-policy&format=markdown#consideration-key-parts)

* [Considerations for defining the Management Utilities security policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialization-security-policy&format=markdown#smart-card-security-plan)

* [Considerations for defining the file security policy](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialization-security-policy&format=markdown#file-security-plan)


## Understanding your responsibilities when using IBM Cloud Hyper Protect Crypto Services
{: #sitemap_understanding_your_responsibilities_when_using_}


[Understanding your responsibilities when using IBM Cloud Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown#shared-responsibilities)

* [Incident and operations management](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown#incident-and-ops)

* [Change management](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown#change-management)

* [Identity and access management](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown#iam-responsibilities)

* [Security and regulation compliance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown#security-compliance)

* [Disaster recovery](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-shared-responsibilities&format=markdown#disaster-recovery)


## High availability and disaster recovery
{: #sitemap_high_availability_and_disaster_recovery}


[High availability and disaster recovery](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-ha-dr&format=markdown#ha-dr)

* [Locations, tenancy, and availability](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-ha-dr&format=markdown#availability)

* [In-region data redundancy and failover](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-ha-dr&format=markdown#data-failover)

* [Cross-region disaster recovery](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-ha-dr&format=markdown#cross-region-disaster-recovery)


## Open-source licenses
{: #sitemap_open-source_licenses}


[Open-source licenses](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-open-source-licenses&format=markdown#open-source-licenses)

* [Hyper Protect Crypto Services notices and information](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-open-source-licenses&format=markdown#notice)

* [Hosting appliance notices and information](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-open-source-licenses&format=markdown#hosting-appliance-notice)


## Resource links
{: #sitemap_resource_links}


[Resource links](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-resources&format=markdown#resources)

* [Videos](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-resources&format=markdown#videos)

* [blogs](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-resources&format=markdown#blogs)


## FAQs
{: #sitemap_faqs}


[General FAQs](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-basics)

* [What's IBM Cloud Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-what-is-hpcs)

* [What is Unified Key Orchestrator?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-what-is-uko)

* [What is a key management service?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-what-key-management)

* [What is Hardware Security Module?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-what-is-hsm)

* [What is a cloud HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-what-is-cloud-hsm)

* [How does Hyper Protect Crypto Services provide a single-tenant cloud service?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-single-tenant)

* [What are the responsibilities of users and IBM Cloud for Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-responsibilities-users-cloud)

* [How is this service different from IBM Cloud HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-differentiators-cloud-hsm)

* [How is Hyper Protect Crypto Services different from Key Protect?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-differentiators-key-protect)

* [How is Keep Your Own Key different from Bring Your Own Key?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-differentiators-KYOK)

* [What can I do with IBM Cloud Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-what-do-with-hpcs)

* [How do I know whether Hyper Protect Crypto Services is right for my company?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-choose-hs-crypto)

* [How does Hyper Protect Crypto Services work?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-how-hpcs-work)

* [What crypto card does Hyper Protect Crypto Services use?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-crypto-card)

* [Which IBM regions are Hyper Protect Crypto Services available in?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-hpcs-regions)

* [I have workloads in a data center where Hyper Protect Crypto Services is not available. Can I still subscribe to this service?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-basics&format=markdown#faq-data-center)

[FAQs: Pricing](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-pricing&format=markdown#faq-pricing)

* [How am I charged for my use of Hyper Protect Crypto Services standard plan?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-pricing&format=markdown#faq-how-charge-hpcs)

* [How am I charged for my use of Hyper Protect Crypto Services with Unified Key Orchestrator?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-pricing&format=markdown#faq-how-charge-hpcs-uko)

* [Is there a free trial for Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-pricing&format=markdown#faq-free-trial)

[FAQs: Provisioning and operations](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-provisioning-operations)

* [Are there any prerequisites for using Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-hpcs-prerequisites)

* [How to initialize Hyper Protect Crypto Services service instances?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-how-to-initialize)

* [Can I initialize my service instance through the TKE CLI plug-in by using a proxy?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-tke-proxy)

* [Are there any recommendations on how to set up smart cards?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-smart-card-setup)

* [How can I procure smart cards and smart card readers?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-procure-smart-card)

* [How many crypto units shall I set up in my service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-crypto-units-number)

* [Can I use Hyper Protect Crypto Services along with other IBM Cloud services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-hpcs-with-cloud-services)

* [How does my application connect to a Hyper Protect Crypto Services service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-application-connection)

* [Can I generate master key on-premises and store the master key parts in the smart cards?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-generate-master-key-on-premises)

* [Can I import root keys from an on-premises HSM?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-import-key-on-premises)

* [Can I use Hyper Protect Crypto Services only for cryptographic operations, but use other IBM Cloud services such as Key Protect for key management?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-hpcs-with-key-protect)

* [Can I use Hyper Protect Crypto Services for applications hosted in other cloud service providers such as AWS, Azure, and GCP?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-hpcs-other-cloud-vendor)

* [How can I know whether the IBM Cloud services that I adopt can integrate with Hyper Protect Crypto Services for key encryption?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-provisioning-operations&format=markdown#faq-hpcs-service-integration)

[FAQs: Hyper Protect Crypto Services Standard Plan](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-performance-capacity&format=markdown#faq-performance-capacity)

* [How many keys can be stored in a Standard Plan instance of Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-performance-capacity&format=markdown#faq-keys-number)

* [How many key rings can be created for a Hyper Protect Crypto Services service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-performance-capacity&format=markdown#faq-keyrings-number)

* [Can I add or remove crypto units after I provision a service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-performance-capacity&format=markdown#faq-add-remove-crypto-unit)

* [Is there a Service Level Agreement (SLA) specifically for Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-performance-capacity&format=markdown#faq-hpcs-sla)

[FAQs: Hyper Protect Crypto Services with Unified Key Orchestrator](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko)

* [How many keys can be stored in a Hyper Protect Crypto Services with Unified Key Orchestrator instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-keys-number-uko)

* [What is the difference between key management, key orchestration, and key governance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-differences)

* [Does Hyper Protect Crypto Services with Unified Key Orchestrator provide key management, governance, and orchestration at the same time?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-functions)

* [Is Unified Key Orchestrator a separate offering?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-offering)

* [How is Hyper Protect Crypto Services with Unified Key Orchestrator different from the Hyper Protect Crypto Services Standard Plan?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-hpcs)

* [What type of HSM is used for Hyper Protect Crypto Services with Unified Key Orchestrator?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-fips)

* [Which cloud vendors or providers are supported by Hyper Protect Crypto Services with Unified Key Orchestrator as connected external keystores?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-vendor-cloud)

* [How is Unified Key Orchestrator different from EKMF Web?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-ekmf)

* [What multizone regions is Hyper Protect Crypto Services with Unified Key Orchestrator available in?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-mzr)

* [Can I still use Hyper Protect Crypto Services with Unified Key Orchestrator for key management even if Hyper Protect Crypto Services is not available in the IBM Cloud region that my service resides in?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-region)

* [How many keystores can be created for an instance of Hyper Protect Crypto Services with Unified Key Orchestrator?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-uko&format=markdown#faq-uko-keystore-number)

[FAQs: Security and compliance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-security-compliance)

* [How can I manage user access to my service instances? Does IBM have access to my instances?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-hpcs-ibm-access)

* [How does IBM offer a unique and secure process for service initialization (key ceremony)?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-hpcs-user-access)

* [What is a 140-2 FIPS Level 4 Certification and how can I validate it?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-fips-level4-meaning)

* [What is the difference between FIPS 140-2 Level 1, 2, 3, and Level 4?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-fips-levels)

* [How to understand the key hierarchy for Hyper Protect Crypto Services KYOK?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-cryptographic-algorithms)

* [How does EP11 differ from PKCS #11?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-ep11-pkcs11)

* [What EP11 mechanisms are supported by the GREP11 functions?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-EP11-mechanisms)

* [What compliance standards does Hyper Protect Crypto Services meet?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-compliance-standards)

* [Can I monitor my service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-security-compliance&format=markdown#faq-monitor-instance)

[FAQs: High availability and disaster recovery](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-ha-dr)

* [How do I set up a high availability configuration?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-ha-configuration)

* [Can I back up my service instance manually?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-backup-manually)

* [What happens if my service instance fails?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-instance-fail)

* [How can I restore the content from backups?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-store-backup)

* [What happens if I delete my service instances?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-delete-instance)

* [Can I back up the keys before I delete a service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-backup-keys)

* [What happens when I delete a key?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-delete-a-key)

* [What happens if I lose the signature key or the master key parts?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-ha-dr&format=markdown#faq-lose-signature-key)

[FAQs: Support and maintenance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-support-maintenance&format=markdown#faq-support-maintenance)

* [How is routine maintenance performed on Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-support-maintenance&format=markdown#faq-routine-maintenance)

* [How do I get support for Hyper Protect Crypto Services?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-support-maintenance&format=markdown#faq-hpcs-support)

* [After the service initialization is done, are there any best practices for managing smart cards or key part files?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-support-maintenance&format=markdown#faq-manage-smartcards)


## Troubleshooting key management service
{: #sitemap_troubleshooting_key_management_service}


[Why am I not authorized to make key management service API request?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-authenticate-api&format=markdown#troubleshoot-unable-to-authenticate-api)

[Why am I receiving a `CKR_IBM_WK_NOT_INITIALIZED` error when I use CLI or API?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-error-CLI-API&format=markdown#troubleshoot-error-CLI-API)

[Why can't I create a standard key after I load another master key?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-create-standard-keys&format=markdown#troubleshoot-unable-to-create-standard-keys)

[Why can't I create or import keys?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-create-keys&format=markdown#troubleshoot-unable-to-create-keys)

[Why can't I delete an initialized service instance?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-delete-instance&format=markdown#troubleshoot-delete-instance)

[Why can't I delete keys?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-delete-keys&format=markdown#troubleshoot-unable-to-delete-keys)

[Why can't I perform any actions by using the UI?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-ui-session-timeout&format=markdown#troubleshoot-ui-session-timeout)

[Why can't I rotate root keys?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-rotate-root-keys&format=markdown#troubleshoot-unable-to-rotate-root-keys)

[Why can't I view or list keys?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-list-keys-api&format=markdown#troubleshoot-unable-to-list-keys-api)

[Why can't I view or list specific keys?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-list-specific-keys&format=markdown#troubleshoot-unable-to-list-specific-keys)


## Troubleshooting master key rotation
{: #sitemap_troubleshooting_master_key_rotation}


[Why can't I rotate master keys by using key part files?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-master-key-rotation-key-part-files&format=markdown#troubleshoot-master-key-rotation-key-part-files)

[Why can't I rotate master keys by using recovery crypto units?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-master-key-rotation-recovery-crypto-units&format=markdown#troubleshoot-master-key-rotation-recovery-crypto-units)

[Why can't I rotate master keys by using smart cards?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-master-key-rotation-key-smart-cards&format=markdown#troubleshoot-master-key-rotation-key-smart-cards)

[Why do I fail to load the new master key during the master key rotation process?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-master-key-rotation&format=markdown#troubleshoot-master-key-rotation)


## Troubleshooting smart cards and the Management Utilities
{: #sitemap_troubleshooting_smart_cards_and_the_management_utilities}


[Why am I not authorized when I start the Trusted Key Entry application?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unauthorized-token-tke-application&format=markdown#troubleshoot-unauthorized-token-tke-application)

[Why am I receiving a blocked PIN on EP11 smart card error?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-block-smart-card&format=markdown#troubleshoot-block-smart-card)

[Why am I receiving a no smart card readers found error when I use the Management Utilities?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-no-smart-card&format=markdown#troubleshoot-no-smart-card)


## Troubleshooting Trusted Key Entry
{: #sitemap_troubleshooting_trusted_key_entry}


[Why am I not authorized when running TKE CLI plug-in commands?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unauthorized-token&format=markdown#troubleshoot-unauthorized-token)

[Why can't I change signature thresholds?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-unable-to-change-signature-thresholds&format=markdown#troubleshoot-unable-to-change-signature-thresholds)

[Why can't I list crypto units?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-list-crypto-units&format=markdown#troubleshoot-list-crypto-units)


## Troubleshooting Unified Key Orchestrator
{: #sitemap_troubleshooting_unified_key_orchestrator}


[Why can't I distribute keys to Azure Key Vault?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-import-azure-key&format=markdown#troubleshoot-import-azure-key)

[Why can't I create internal keystores?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-create-internal-keystores&format=markdown#troubleshoot-create-internal-keystores)

[Why can't I create vaults?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-create-vault&format=markdown#troubleshoot-create-vault)

[Why can't I delete vaults?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-delete-vault&format=markdown#troubleshoot-delete-vault)

[Why can't I delete internal keystores?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-delete-keystore&format=markdown#troubleshoot-delete-keystore)

[Why do I fail to see the changes to my key in Azure Key Vault?](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-troubleshoot-azure-delay&format=markdown#troubleshoot-azure-delay)


## Getting help and support for Hyper Protect Crypto Services
{: #sitemap_getting_help_and_support_for_}


[Getting help and support for Hyper Protect Crypto Services](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-getting-help&format=markdown#getting-help)

* [Providing support case details](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-getting-help&format=markdown#support-case-details)