Verify your environment meets these requirements.
Supported hardware
- CryptoHub
7.3.0.x or later.
Supported operating systems
Required access
- An account on the CryptoHub with administrator permissions to deploy new services.
- Local administrator/root access on the computer where OpenSSL Engine is installed.
Network and firewall
- Allow outbound TCP port 443 from the computer running OpenSSL Engine to the CryptoHub REST API, specified by FQDN (for example,
cryptohub.example.com) or CIDR (for example, 203.0.113.0/24).
TLS inspection or SSL proxies can break mutual TLS handshakes. Exempt the CryptoHub FQDN(s) from inspection. Configure the CryptoHub with a FQDN so the exemption applies.
Other
- OpenSSL 1.1.x or 3.x using the ENGINE interface. On OpenSSL 3.x, Futurex recommends the OpenSSL provider path instead; use this ENGINE path for OpenSSL 1.1.x or where an existing application still relies on the engine interface.
- OpenSC and libp11 0.4.21. Earlier libp11 builds can fail when OpenSSL 3 loads a CryptoHub-backed key through ENGINE.