Integration Requirements and Prerequisites

Tested Versions

Operating System

Partner Product

Utimaco SecurityServer Version

Utimaco HSM

Linux (containerized deployment)

Para Vault 6.8

6.3.0

u.trust GP HSM Se-Series

Tested versions

Hardware and Software Requirements

Hardware

Hardware Requirements

Utimaco LAN HSM

u.trust GP HSM Se-Series LAN with firmware SecurityServer 6.3.0 or higher

Utimaco PCI-e HSM

u.trust GP HSM Se-Series PCI-e with firmware SecurityServer 6.3.0 or higher

List of hardware requirements

Software

Software Requirements

HSM Interface

SecurityServer PKCS#11 Provider

HSM Tool

PKCS#11 Tool version 2 (p11tool2)

Para Vault image

An HSM-capable Para Vault image (includes PKCS#11 hardware-protection capability; see Prerequisites)

Host tools

openssl ≥ 1.1.0 (used by epv-hsm to encrypt/decrypt the PIN); Docker/Docker Compose

List of software requirements

Prerequisites

Before you begin, confirm that:

  • The Utimaco u.trust GP HSM has been deployed and configured.

  • An MBK has been created and saved for each HSM (see the CryptoServer documentation).

  • The CryptoServer default administrator has been replaced with a new administrator user.

  • The operating system matches the Tested Versions.

  • The SecurityServer version matches the Tested Versions.

  • The PKCS#11 library has been installed and configured for the environment (see the CryptoServer documentation).

  • You have the administrator privileges required to install software.

  • Para Vault has been deployed and is running normally.

  • Para Vault uses an HSM-capable image: This image has built-in PKCS#11 hardware-protection capability and includes a hardware-protection configuration section in its configuration template. If the current Para Vault uses an image without this capability, first upgrade to an HSM-capable Para Vault image.

  • You have registered an account and obtained download permission from the Utimaco Support Portal.

Installing and deploying Para Vault is out of scope for this document.