This guide is part of the information and support provided by Utimaco. Additional documentation produced to support your Utimaco SecurityServer product can be found in the document directory of the Utimaco SecurityServer product bundle.
All Utimaco SecurityServer product documentation is available from Utimaco’s website at https://utimaco.com/.
About This Guide
This guide provides an integration guide explaining how to integrate an Utimaco CryptoServer Hardware Security Module (HSM) with OpenXPKI. Utimaco securely generates and stores the private keys of Root CA and Issuing CA used by OpenXPKI.
Target Audience for This Guide
This guide is intended for administrators of OpenXPKI Administrator and of Utimaco HSMs.
Document Conventions
The following conventions are used in this guide:
|
Convention |
Use |
Example |
|---|---|---|
|
Bold |
Items of the Graphical User Interface (GUI), e.g., menu options |
Select Details and click on Properties button |
|
|
Code that is given for explanation or as an example, file paths |
|
|
Italic |
References and important terms |
Operating system listed in Tested Versions |
Document conventions
We use special icons to highlight the most important notes and information.
Here you will find important safety information that should be followed.
Here you will find additional notes or supplementary information.
This message marks the result expected after the successful execution of an instruction.
Abbreviations
The following abbreviations are used in this guide:
|
Abbreviation |
Meaning |
|---|---|
|
CA |
Certificate Authority |
|
CRL |
Certificate Revocation List |
|
CSADM |
CryptoServer Command-line Administration Tool |
|
CSR |
Certificate Signing Request |
|
FCGI |
Fast Common Gateway Interface |
|
GPG |
GNU Privacy Guard |
|
GUI |
Graphical User Interface |
|
HSM |
Hardware Security Module |
|
LAN |
Local Area Network |
|
MBK |
Master Backup Key |
|
OS |
Operating System |
|
PCIe |
PCI Express Interface |
|
PIN |
Personal Identification number |
|
PKI |
Public Key Infrastructure |
|
PKCS#11 |
Public-Key Cryptography Standard #11 |
|
RA |
Registration Authority |
|
RDBMS |
Relational Database Management Systems |
|
RSA |
Rivest, Shamir, Adleman (cryptosystem) |
|
SCEP |
Simple Certificate Enrollment Protocol |
|
TLS |
Transport Layer Security |
|
UI |
User Interface |
|
URL |
Uniform Resource Locator |
List of abbreviations