Configuration on Kron PAM

The configuration is split into three logical phases. The first phase deploys the Utimaco vendor libraries to the correct locations on the Kron PAM server. The second phase creates the configuration files that establish the connection between the PKCS#11 layer and the Utimaco u.trust GP HSM appliance. The third phase registers the HSM with Kron PAM's security subsystem and performs key migration if necessary. 

Each step below includes an explanation of what is being done and why, followed by the exact commands or file contents to use.