Tested Versions
|
Operating System |
Partner Product |
Utimaco SecurityServer Version |
Utimaco HSM |
|---|---|---|---|
|
Linux (containerized deployment) |
Para Vault 6.8 |
6.3.0 |
u.trust GP HSM Se-Series |
Tested versions
Hardware and Software Requirements
|
Hardware |
Hardware Requirements |
|---|---|
|
Utimaco LAN HSM |
u.trust GP HSM Se-Series LAN with firmware SecurityServer 6.3.0 or higher |
|
Utimaco PCI-e HSM |
u.trust GP HSM Se-Series PCI-e with firmware SecurityServer 6.3.0 or higher |
List of hardware requirements
|
Software |
Software Requirements |
|---|---|
|
HSM Interface |
SecurityServer PKCS#11 Provider |
|
HSM Tool |
PKCS#11 Tool version 2 (p11tool2) |
|
Para Vault image |
An HSM-capable Para Vault image (includes PKCS#11 hardware-protection capability; see Prerequisites) |
|
Host tools |
openssl ≥ 1.1.0 (used by epv-hsm to encrypt/decrypt the PIN); Docker/Docker Compose |
List of software requirements
Prerequisites
Before you begin, confirm that:
-
The Utimaco u.trust GP HSM has been deployed and configured.
-
An MBK has been created and saved for each HSM (see the CryptoServer documentation).
-
The CryptoServer default administrator has been replaced with a new administrator user.
-
The operating system matches the Tested Versions.
-
The SecurityServer version matches the Tested Versions.
-
The PKCS#11 library has been installed and configured for the environment (see the CryptoServer documentation).
-
You have the administrator privileges required to install software.
-
Para Vault has been deployed and is running normally.
-
Para Vault uses an HSM-capable image: This image has built-in PKCS#11 hardware-protection capability and includes a hardware-protection configuration section in its configuration template. If the current Para Vault uses an image without this capability, first upgrade to an HSM-capable Para Vault image.
-
You have registered an account and obtained download permission from the Utimaco Support Portal.
Installing and deploying Para Vault is out of scope for this document.