phoenixNAP EMP Account Provisioning and Overview

Introduction

The phoenixNAP Encryption Management Platform simplifies encryption key management and ensures the highest level of data protection. Powered by Fortanix Self-Defending Key Management Service (SDKMS), it is a secure system for safeguarding encryption keys, secrets, and tokens.

Get acquainted with phoenxNAP’s EMP and learn how to create, manage, and maintain accounts and users.

phoenixNAP EMP account provisioning and overview.

phoenixNAP EMP Benefits

The main benefits of using the phoenixNAP Encryption Management Platform include:

  • Centralized control in a single tool.
  • Data security across multi-cloud infrastructures and multiple cloud providers.
  • Main control of all keys.
  • Easier app security implementation using RESTful APIs.
  • Scaling dynamically and as needed.
  • Lowering costs by using EMP on-demand.
  • Integrated security for all data protection needs.

Account Provisioning and Overview

The platform has a centralized and intuitive web UI with role-based access control, single sign-on, and auditing integration with SIEM tools. 

Create an Account

To create a new EMP account, fill out the phoenixNAP EMP Sign up form. The information provided creates the administrator user for the account.

  1. Provide an email address, first name, last name, and a strong password to protect the account.
  2. Click the SIGN UP button.
Sign up for a new phoenixNAP EMP account.
  1. A system administrator needs to approve the creation of a new account. Therefore, you need to submit an official request. Type in an account name and a reason for creating the account. Click SUBMIT REQUEST to complete.
Submit a request to create a new EMP account.

Log in to Your Account

If you already have an existing phoenixNAP EMP account, navigate to the phoenixNAP EMP page.

  1. Type in your email address and click LOG IN.
Log in to EMP account.
  1. Provide the password for the given account and click LOG IN to move to the Fortanix dashboard.
Provide password for EMP account.

Once you log in to your account, you will see the phoenixNAP EMP dashboard powered by Fortanix. It has an intuitive user interface easy to navigate through.

The sidebar on the left lists all the features you can manage and configure. 

phoenixNAP EMP Fortanix dashboard.

Groups

A group is a collection of relate security objects. Users and applications that are assigned to a specific group can create and access the security objects within it. This is managed by access policies set at group level.

Groups can have an unlimited number of users and applications. Additionally, users and applications can belong to multiple groups. The user who created the group is assigned the group administrator.

To create a new group:

  1. Navigate to the Groups menu option in the sidebar.
  2. If you don’t have any groups yet, click the CREATE NEW GROUP button. Alternatively, you can add a new group using the plus icon.
Create a new group in EMP.
  1. Provide a title (which you can change later).
  2. Add a description for the group. This helps identify groups in your system.
  3. Add a LINK HSM/EXTERNAL KMS if needed and a quorum approval policy for additional security.
  4. SAVE to complete. The new group appears listed in the All Groups section.
An example of a group on EMP.

To edit an existing group:

Hover over the name in the All Groups section. A light blue menu with five options appears on the right side of the row. It allows you to:

Options for editing an EMP group.

Applications

Applications are services, daemons, and other non-human clients that use, generate, and store security objects. They interact with the EMP using REST APIs, PKCS#11 or CNG providers.

To add an application:

  1. Select Apps from the sidebar navigation.
  2. If you don’t have any apps yet, use the CREATE NEW APP button. To add a new app, click the plus sign.
Create a new app on EMP.
  1. Type in the app name and choose an interface (optional).
  2. You can also add a description and define the application type.
  3. Next, select the authentication method choosing between an API key, certificate, trusted CA, Google service account, JSON web token, and external directory.
Configuring a new app onto EMP.
  1. Decide whether you want to enable OAuth. By doing so, users can authorize the app to perform actions on their behalf.
  2. Finally, assign the app to a group and SAVE the configuration.
  3. Use the API key or certificate and authenticate the application.
An example of an application on EMP.

Security Objects

Security objects are keys, certificates, secretes, and any other datum stored on the EMP. Users have to be assigned to the appropriate group to have permission to see and use security objects.

To create a new security object:

  1. Navigate to the Security Objects (SO) section.
  2. Add a new SO by clicking the plus icon or on CREATE SECURITY OBJECT.
Creating a new security object.
  1. Provide a security object name.
  2. Select a group to which it should belong to.
  3. Optionally, add a description for this instance.
  4. Then, choose whether you want to import or generate the security object.
Configuring a new security object using EMP.
  1. Configure the SO by defining the type, data type, key size, and other settings.
    You should see the newly created security object on the main page of the section. Click on the object for more information or use the shortcut icons to:
    • Copy the UUID.
    • Edit state/Restrict permissions.
    • Download logs.
Options for editing an existing security object.

Note: Learn how to set up BMC drive encryption using EMP to protect sensitive information. Additionally, refer to our guide How to Provision and Secure Tokens and Secrets in EMP for more information on security objects.

Users

Users can be members of one or more accounts and belong to one more multiple groups. Each user is associated with an email address.

Depending on the privileges it has, a user can add or modify the users/groups, create, and change properties of security objects, review cryptographic activity and logs of key management.

To add a new user to an account:

  1. Open the Users section from the sidebar navigation.
  2. The account administrator will already be listed in the user list.
  3. Click the plus icon.
Add a new user to an account.
  1. Provide the email address of the new user you want to add. Alternatively, search the LDAP directory (The Lightweight Directory Access Protocol). For this, you need to have LDAP integrations configured.
  2. Choose the type of account the user will have – member, administrator, or auditor. Click Next to continue.
Types of accounts users can have in phoenixNAP EMP.
  1. Then, assign the new user to one or multiple groups.
  2. Finally, select whether the user will have an Auditor or Administrator role in the group. The administrator role gives full access to the group, while auditors have read-only access.
Selecting a user role.
  1. The new user receives an email with an invitation to join the account on Fortanix Self-Defending KMS. To complete adding the user to an account, he/she needs to accept the invitation.
An example of an email invitation to join an account on phoenixnNAP Encryption Management Platform.

Plugins

A plugin allows users to run sensitive business logic securely. Plugins are powerful systems used for imposing access control policies on keys, managing which certificates can be signed, implementing cryptographic operations, and many other tasks.

To add a new plugin to an account:

  1. Navigate to the Plugins section.
  2. Click the NEW PLUGIN button.
Create a new plugin on EMP.
  1. Create/import a new plugin by uploading a file with plugin code or typing the code inline. Alternatively, browse the plugin library to add a preloaded, tested, and rated plugin to the account.

The Plugin Library consists of the most frequently used plugins. The library is regularly updated with new plugins you can add to the account. If there is a group of plugins you intend to use, the platform allows you to create local copies in a separate library.

Tasks

The Tasks section shows all the pending, completed, and failed tasks run on the account. It includes an Approval tab where it lists all the tasks that need to be approved, and an Import/Export tab.

See tasks on EMP account.

Audit Log

The encryption management platform keeps an internal audit log of all system operations performed on the account. EMP maintains logs automatically and can pass them on to other logging systems.

To learn more about Audit Logs, check out the Fortanix User's Guide: Logging.

In the image below, you see an example of an audit log.

View audit login for EMP account.

Note: Your cluster needs have Internet access to be able to access the Plugin Library.

Conclusion

After reading this article, you should know how phoenixNAP EMP account provisioning works and have a general sense of how the platform functions and which features it provides.

phoenixNAP EMP simplifies the management of all your HSM licenses, secrets, and tokens using a single interface. Start using EMP and provide the highest level of protection for your data.

Was this article helpful?
YesNo
Sofija Simic
Sofija Simic is an experienced Technical Writer. Alongside her educational background in teaching and writing, she has had a lifelong passion for information technology. She is committed to unscrambling confusing IT concepts and streamlining intricate software installations.
Next you should read
How VMware Tenants Apply the Fortanix Encryption Policy
January 14, 2021

The steps in this guide explain how to apply the EMP (Fortanix) storage policy to a virtual machine as a tenant.
Read more
Install and Configure Veeam Management Agent and Veeam Backup Agent
August 6, 2020

This guide will help you log into the Veeam Availability Console and install the necessary tools you need to start a backup job.
Read more
Performing a Bare Metal Restore from Veeam Cloud Connect
August 20, 2020

This guide will show you how to create a recovery media and perform a restore operation on a VM.
Read more
How to Connect to a Server Using the BMC Remote Console Feature
August 28, 2020

Follow the instructions in this guide to learn how to access a Bare Metal Cloud server via Remote Console.
Read more