Ensure that the system environment you will be using meets the following hardware and software requirements.
This guide assumes that the user has already installed and configured required software.
Tested Versions
The integrations that have been successfully tested with the Utimaco HSM with LUKS.
|
Operating System |
OpenSSL Version |
Systemd- cryptenroll Version |
Cryptsetup Version |
Utimaco Security Server Version |
Utimaco HSM |
|---|---|---|---|---|---|
|
Fedora 37 Fedora 36 |
OpenSSL 3.0.5 |
systemd 250 (250- 8) |
cryptsetup 2.4.3 |
SecurityServer 4.50.0.2 |
CryptoServer CSeSeries/Se-Series |
List of tested versions
LUKS integration with Utimaco HSM is not supported with RHEL 9 as RHEL 9 does not have PKCS11 library (libcryptsetup-token-systemd-pkcs11.so) for cryptsetup.
Software Requirements
|
Software |
Software Requirements |
|---|---|
|
HSM Interfaces |
PKCS11 |
|
OpenSSL |
3.0.5 |
|
Libp11 |
libp11-0.4.12 |
|
System-cryptenroll |
systemd 250 (250-8) |
|
Cryptsetup Version |
cryptsetup 2.4.3 |
List of software requirements
Hardware Requirements
|
Hardware |
Hardware Requirements |
|---|---|
|
Utimaco LAN HSM |
CryptoServer CSe-Series/Se-Series LAN with firmware SecurityServer 4.50.0.2 or higher |
|
Utimaco PCI-e HSM |
CryptoServer CSe-Series/Se-Series PCI-e with firmware SecurityServer 4.50.0.2 or higher |
List of hardware requirements
Set up an account on the Utimaco support portal and request download access at the following URL https://support.hsm.utimaco.com/ .
Prerequisites
Before you begin, please ensure that:
-
The CryptoServer is set up and configured. Refer to the CryptoServer documentation to set up the HSM.
-
The MBK has been created and stored onto each HSM. Refer to the CryptoServer documentation to set up the MBK.
-
The CryptoServer Default Admin has been replaced with a new admin user.
-
The operating system is listed in Tested Versions.
-
The SecurityServer is listed in Tested Version.
-
There is an admin user set up as it is required for installing software.