If
you use the DHE or ECDHE key exchange algorithms to enable perfect forward
secrecy (PFS) support for SSL decryption, you can use an HSM to
store the private keys for SSL Inbound Inspection. You can also
use an HSM to store ECDSA keys used for SSL Forward Proxy or SSL
Inbound Inspection decryption.