Supported versions
Use the following versions for this guide:
KMIP is a network protocol, so the application host can run any operating system that the application supports. No Futurex software is installed on the application host.
Required access
- Obtain two CryptoHub administrator identities. Dual control protects service and endpoint deployment.
- Obtain administrative access to the application’s key-management or external key manager settings. Most applications restrict KMIP server configuration to administrators.
- Prepare a protected location for the endpoint download. It contains the client private key and the password for the PKCS #12 file.
Network and TLS
- Allow outbound TCP 5696 from the application host to the CryptoHub FQDN. TCP 5696 is the KMIP port.
- Allow administrators to reach the CryptoHub web interface on TCP 443. The application itself does not use TCP 443.
- Configure DNS so the CryptoHub FQDN resolves from the application host.
- Keep server certificate verification enabled in the application’s KMIP settings.
- The KMIP port accepts TLS 1.2 and TLS 1.3 and uses the TLS extended master secret extension.
Application requirements
- Identify the application’s KMIP settings. Record the fields it requires for the server address, port, client certificate, client private key, server CA, and optional username and password.
- Identify the certificate format the application accepts, for example separate PEM files, a combined PEM file, or a PKCS #12 file.
- Identify whether the application requires an RSA or ECC client certificate. The endpoint dialog creates either type.
- Identify whether the application retrieves key material or requests server-side operations.

