Introduction

This guide is part of the information and support provided by Utimaco. Additional documentation produced to support your Utimaco SecurityServer product can be found in the document directory of the Utimaco SecurityServer product bundle.

All Utimaco SecurityServer product documentation is available from Utimaco’s website at https://utimaco.com/.

About This Guide

This guide provides an integration guide explaining how to integrate an Utimaco CryptoServer Hardware Security Module (HSM) with OpenXPKI. Utimaco securely generates and stores the private keys of Root CA and Issuing CA used by OpenXPKI.

Target Audience for This Guide

This guide is intended for administrators of OpenXPKI Administrator and of Utimaco HSMs.

Document Conventions

The following conventions are used in this guide:

Convention

Use

Example

Bold

Items of the Graphical User Interface (GUI), e.g., menu options

Select Details and click on Properties button

Monospaced

Code that is given for explanation or as an example, file paths

certreq.exe -new request.inf IISCertRequest.csr

Italic

References and important terms

Operating system listed in Tested Versions

Document conventions

We use special icons to highlight the most important notes and information.

Here you will find important safety information that should be followed.

Here you will find additional notes or supplementary information.

This message marks the result expected after the successful execution of an instruction.

Abbreviations

The following abbreviations are used in this guide:


Abbreviation

Meaning

CA

Certificate Authority

CRL

Certificate Revocation List

CSADM

CryptoServer Command-line Administration Tool

CSR

Certificate Signing Request

FCGI

Fast Common Gateway Interface

GPG

GNU Privacy Guard

GUI

Graphical User Interface

HSM

Hardware Security Module

LAN

Local Area Network

MBK

Master Backup Key

OS

Operating System

PCIe

PCI Express Interface

PIN

Personal Identification number

PKI

Public Key Infrastructure

PKCS#11

Public-Key Cryptography Standard #11

RA

Registration Authority

RDBMS

Relational Database Management Systems

RSA

Rivest, Shamir, Adleman (cryptosystem)

SCEP

Simple Certificate Enrollment Protocol

TLS

Transport Layer Security

UI

User Interface

URL

Uniform Resource Locator

List of abbreviations