Ensure the system environment you will be using meets the following hardware and software requirements.
Tested Versions
The integrations that have been successfully tested with the Utimaco HSM with OpenXPKI.
|
Operating System |
OpenXPKI Version |
Utimaco Security Server Version |
Utimaco HSM |
|---|---|---|---|
|
Debian 12 |
3.26.0 |
SecurityServer 4.55.0.0
|
CryptoServer CSe-Series/Se-Series u.trust Anchor Se*k and u.trust Anchor CSAR |
List of tested versions
Software Requirements
|
Software |
Software Requirements |
|---|---|
|
HSM Utility |
PKCS#11 Tool Version 2 (p11tool2) |
|
HSM Interfaces |
SecurityServer PKCS#11 Provider |
List of software requirements
Hardware Requirements
|
Hardware |
Hardware Requirements |
|---|---|
|
Utimaco LAN HSM |
CryptoServer CSe-Series/Se-Series LAN with firmware SecurityServer 4.55.0.0 or higher u.trust Anchor Se*k and CSAR Series LAN with firmware 4.55.0.0 or higher |
|
Utimaco PCI-e HSM |
CryptoServer CSe-Series/Se-Series PCI-e with firmware SecurityServer 4.55.0.0 or higher u.trust Anchor Se*k and CSAR Series PCI-e with firmware 4.55.0.0 or higher |
List of hardware requirements
Set up an account on the Utimaco support portal and request download access at the following URL https://support.hsm.utimaco.com/.
3.4 Prerequisites
Before you begin, please ensure that:
-
The Utimaco CryptoServer HSM is set up and configured. Refer to the CryptoServer documentation to set up the HSM.
-
The MBK has been created and stored onto each HSM. Refer to the CryptoServer documentation to set up the MBK.
-
The CryptoServer Default Admin has been replaced with a new admin user.
-
The operating system used is listed in Tested Versions.
-
The SecurityServer is listed in Tested Versions.
-
The PKCS#11 library is set up and configured as per your environment.
-
You refer to the CryptoServer documentation to set up and configure the PKCS#11 library.
-
You have a user with root privileges as it is required to install the packages.
-
You allow port 8080 through the firewall.