Integration Requirements and Prerequisites

Tested Versions

Operating System

Paraview API Security Gateway

Utimaco SecurityServer Version

Quantum Protect

Utimaco HSM

Linux x86-64

v7.0

6.3.0.0

1.5.0.0 ( a5 ML / a6
PQMI / a2 HBS all
INIT_OK )

CryptoServer CSe-Series / Se-
Series (LAN or PCIe), or the
bl_sim5 simulator for evaluation

Tested versions

The procedures in this guide are based on the standard PKCS#11 interface. The table above lists the tested combination; for physical LAN/PCIe models, deploy the corresponding firmware version.

Hardware and Software Requirements

Hardware

Hardware Requirements

Utimaco LAN HSM

CryptoServer CSe/Se-Series LAN, SecurityServer 6.3.0.0 or later, with Quantum Protect 1.5.0.0 firmware loaded

Utimaco PCIe HSM

CryptoServer CSe/Se-Series PCIe, SecurityServer 6.3.0.0 or later, with Quantum Protect 1.5.0.0 firmware loaded

Network

The gateway nodes and the management console node can both route to the HSM service port

List of hardware requirements

Software

Software Requirements

System OpenSSL

3.5 or later on every gateway node (native ML-DSA/ML-KEM support). This is a hard prerequisite for post-quantum capability

Product Image

Must be the HSM-enabled build. HSM support is an optional capability of the product image; confirm with your delivery contact that the deployed image includes it — otherwise the HSM operations in this guide report an explicit "HSM support not available" result

Utimaco PKCS#11 Library

libcs_pkcs11_R3.so , from the u.trust GP HSM Product Bundle / SecurityServer software package.

Utimaco Management Tools

csadm (device management) and p11tool2 (PKCS#11 slot and PIN management)

Probing Tool (Optional)

OpenSC pkcs11-tool , for a quick check of slots and tokens

List of software requirements

Prerequisites

Before proceeding with the integration, ensure that the following prerequisites are met:

  • The product is deployed and running normally, and you can sign in to the management console as a security officer.

  • The Utimaco CryptoServer HSM is deployed and basic configuration is complete (see the official CryptoServer documentation).

  • An MBK has been created and safely stored for every HSM.

  • The default CryptoServer administrator has been replaced with a newly created administrator user.

  • Quantum Protect firmware is loaded and a5 ML , a6 PQMI and a2 HBS are all INIT_OK (verification in Confirming the Post Quantum Firmware Modules ).

  • The system OpenSSL on every gateway node is 3.5 or later (in domestic-stack or offline environments, verify the version in the base image).

  • The product's encryption key ( STOA_ENCRYPTION_KEY , 32 bytes base64) is configured, and every gateway node uses the same value as the management console (see Encryption Key Consistency).

  • You have the administrative privileges required to install software on the nodes.

  • You have download permissions on the Utimaco support portal: https://support.hsm.utimaco.com/