Set up a Sample Signer Using an HSM Crypto Token

To set up a sample signer by using an HSM crypto token, do the following:

  1. Click on Add below the workers' list (See Figure 3).

  2. Click on From Template, select pdfsigner.properties in the list menu, and click on Next.

image-3284599127-1.jpg

PdfSigner Template example

  1. Edit the signer settings in the configuration text area and change the WORKERGENID1.CRYPTOTOKEN setting to use the commented-out sample by using the PKCS#11 crypto token, CryptoTokenP11, to match the crypto token set up.

  2. Click on Apply.

image-3284599127-2.jpg

Signserver PdfSigner Configuration example

  1. Set the DEFAULTKEY worker property by clicking on the new signer, click on Configuration and then click the Edit link in the table row for the DEFAULTKEY property.

image-3284599127-3.jpg

Signserver select PdfSigner

  1. Enter the key alias for the newly generated key in the HSM into the Value text area and click on Submit.

image-3284599127-4.jpg

PdfSigner configuration example

  1. Install the signer certificate chain as issued by your CA:

    1. Click the link to your PKCS#11 crypto worker in the workers' list and click on Install certificates.

  2. Click the > button to select your key generated previously.

  3. Click on Browse and select your issued certificate chain.

  4. Select Install in token and click on Install.

image-3284599127-5.jpg

Signserver PdfSigner certificate install

  1. To activate the new signer, select the link to the new signer in the workers list, and click on Activate.

  2. Enter the HSM slot PIN and click on Activate.