HSM integration via the EJBCA Web Interface

The most straight forward way to configure an Utimaco HSM with your CA is via the Web interface of EJBCA installation. To do so, login in to the administrator’s interface as described in the EJBCA user’s guide and proceed with the generation of a new CA. In the configuration menu, select the hard Token as the CA’s token option and in the field that opens enter the properties given next.

slot 1

defaultKey defaultKey  
certSignKey signKey  
crlSignKey signKey  
testKey testKey  
pin user1  
sharedLibrary /etc/utimaco/libcs2_pkcs11.so  

The shared library path given previously is custom and thus caution has to be taken for your EJBCA to find the location where the library is placed. When all the fields have been filled, press the generate button and a new HSM based CA is created (Please see EJBCA user manual for details).