Integration Requirements and Prerequisites

Ensure the system environment you will be using meets the following hardware and software requirements.

Tested Versions

The integrations that have been successfully tested with the Utimaco HSM with OpenXPKI.

Operating System

OpenXPKI Version

Utimaco Security Server Version

Utimaco HSM

Debian 12

3.26.0

SecurityServer 4.55.0.0


CryptoServer

CSe-Series/Se-Series

u.trust Anchor Se*k and

u.trust Anchor CSAR

List of tested versions

Software Requirements

Software

Software Requirements

HSM Utility

PKCS#11 Tool Version 2 (p11tool2)

HSM Interfaces

SecurityServer PKCS#11 Provider

List of software requirements

Hardware Requirements

Hardware

Hardware Requirements

Utimaco LAN HSM

CryptoServer CSe-Series/Se-Series LAN with firmware SecurityServer

4.55.0.0 or higher

u.trust Anchor Se*k and CSAR Series LAN with firmware 4.55.0.0 or higher

Utimaco PCI-e HSM

CryptoServer CSe-Series/Se-Series PCI-e with firmware SecurityServer

4.55.0.0 or higher

u.trust Anchor Se*k and CSAR Series PCI-e with firmware 4.55.0.0 or higher

List of hardware requirements

Set up an account on the Utimaco support portal and request download access at the following URL https://support.hsm.utimaco.com/.

3.4 Prerequisites

Before you begin, please ensure that:

  • The Utimaco CryptoServer HSM is set up and configured. Refer to the CryptoServer documentation to set up the HSM.

  • The MBK has been created and stored onto each HSM. Refer to the CryptoServer documentation to set up the MBK.

  • The CryptoServer Default Admin has been replaced with a new admin user.

  • The operating system used is listed in Tested Versions.

  • The SecurityServer is listed in Tested Versions.

  • The PKCS#11 library is set up and configured as per your environment.

  • You refer to the CryptoServer documentation to set up and configure the PKCS#11 library.

  • You have a user with root privileges as it is required to install the packages.

  • You allow port 8080 through the firewall.