Tested Versions
|
Operating System |
Ascertia ADSS Server |
Utimaco SecurityServer Version |
Utimaco HSM |
|---|---|---|---|
|
Windows Server 2022 |
8.3.10 |
SecurityServer 6.4.0 |
u.trust GP HSM
|
|
RHEL 9 |
8.3.10 |
SecurityServer 6.4.0 |
u.trust GP HSM
|
Tested versions
Hardware and Software Requirements
|
Hardware |
Hardware Requirements |
|---|---|
|
Utimaco LAN HSM |
u.trust GP HSM CSe-Series/Se-Series LAN with firmware
|
|
Utimaco PCI-e HSM |
u.trust GP HSM CSe-Series/Se-Series PCI-e with firmware
|
List of hardware requirements
|
Software |
Software Requirements |
|---|---|
|
HSM Interface |
SecurityServer PKCS#11 Provider |
|
Ascertia ADSS Server |
8.3.10 |
List of software requirements
Prerequisites
Before you begin, please ensure that you have:
-
Installed and set up the operating system listed in Tested Versions.
-
Installed and set up the HSM listed in Tested Versions.
-
Replaced the HSM default admin with a new admin user.
-
Created and stored the MBK on each HSM. Refer to the u.trust GP HSM documentation to
set up the MBK. -
Set up and configure the u.trust GP HSM. Refer to the u.trust GP HSM documentation to
set up the HSM. -
Set up and configured the PKCS#11 library according to your environment. Refer to the
u.trust GP HSM documentation for instructions on setting up and configuring the PKCS#11
library. -
Created the Security Officer (SO) user and Crypto user.
-
The HSM appliance is powered on and accessible on the network at a known IP address
and port (default: 4001–4031). -
A user account exists with sufficient privileges to log in and perform key operations. The
username and PIN must be available. -
An AES-256 Secret Key Object has been created on the Utimaco u.trust GP HSM and given
a label (alias). This guide uses pam-master-key as the label throughout. Note this value — it
will be referenced in multiple configuration files. -
The Utimaco vendor client package has been provided by Utimaco support. This package
contains thelibcs_pkcs11_R3.soshared library and theCryptoServerJCE.jarfile.