Skip to main content
Prepare the CryptoHub service, the KMIP application, the network path, and protected storage for the endpoint TLS files before you configure the integration.

Supported versions

Use the following versions for this guide: KMIP is a network protocol, so the application host can run any operating system that the application supports. No Futurex software is installed on the application host.

Required access

  • Obtain two CryptoHub administrator identities. Dual control protects service and endpoint deployment.
  • Obtain administrative access to the application’s key-management or external key manager settings. Most applications restrict KMIP server configuration to administrators.
  • Prepare a protected location for the endpoint download. It contains the client private key and the password for the PKCS #12 file.

Network and TLS

  • Allow outbound TCP 5696 from the application host to the CryptoHub FQDN. TCP 5696 is the KMIP port.
  • Allow administrators to reach the CryptoHub web interface on TCP 443. The application itself does not use TCP 443.
  • Configure DNS so the CryptoHub FQDN resolves from the application host.
  • Keep server certificate verification enabled in the application’s KMIP settings.
  • The KMIP port accepts TLS 1.2 and TLS 1.3 and uses the TLS extended master secret extension.
TLS inspection terminates the connection before it reaches CryptoHub and breaks mutual TLS. Exempt the CryptoHub FQDN and TCP 5696 from TLS inspection.

Application requirements

  • Identify the application’s KMIP settings. Record the fields it requires for the server address, port, client certificate, client private key, server CA, and optional username and password.
  • Identify the certificate format the application accepts, for example separate PEM files, a combined PEM file, or a PKCS #12 file.
  • Identify whether the application requires an RSA or ECC client certificate. The endpoint dialog creates either type.
  • Identify whether the application retrieves key material or requests server-side operations.