Download and Install Utimaco Software
If you have not already done so, please create and request an Utimaco Support Portal Account. This will allow you to download the software components needed for this installation.
-
Copy the downloaded software at the appropriate location on the Server.
-
Create an
utimacofolder under the/optdirectory and further create 2 directories:-
/opt/utimaco/bin -
/opt/utimaco/lib
-
|
|
|---|
|
|
-
Copy pkcs11 library file
libcs_pkcs11_R3.sofrom Utimaco CryptoServer software to the/opt/utimaco/libdirectory.
|
|
|---|
|
|
-
Copy the
csadmandp11tool2files from Utimaco CryptoServer software to/opt/utimaco/bindirectory and make both files executable.
|
|
|---|
|
|
u.trust GP HSM PKCS#11 Configuration
-
Create the directory
/etc/utimaco. Locate the Utimaco PKCS#11 configuration file in your SecurityServer directory,Linux/x86-64/Crypto_APIS/PKCS11_R3/sample. Copy the Utimaco PKCS#11 configuration filecs_pkcs11_R3.cfginto the/etc/utimacodirectory.
|
|
|---|
|
|
-
Edit the
cs_pkcs11_R3.cfgfile and make the appropriate changes to the file.
|
|
|---|
|
|
This integration is not supported with external keystore.
For more information regarding the commands and command parameters, please check the Utimaco CryptoServer documentation. The device may be a CryptoServer (PCIe or LAN) device. The device line will follow one of these patterns, based on the HSM form-factor:
Device = 288@<HSM IP address> Hardware (LAN) HSM
or
Device = /dev/cs2.0 Hardware (PCIe) HSM
To make your testing easier, it would be good to enable the PKCS#11 log file. That can be enabled by editing the Logging Loglevel. Set the LogPath and Logging Loglevel to 1. For testing you may want to increase it to 4.
The added LogPath points to a writable directory, not to a file.
If you encounter problems, check the log file named cs_pkcs11_R3.log in the LogPath defined directory. When you are done testing, you should change Logging to 1 or 2. This will limit the logging to only critical and important messages.
Create SO, User and Initialize a Slot
You must initialize a slot with a custom label using p11tool2.
First using p11tool2 create, the SO or Security Officer and then using the p11tool2 command initialize the Slot that you want to use, as well as the slot user, as shown below.
|
|
|---|
|
|