> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Before you start

> Prepare CryptoHub, the KMIP application, identity, TLS, and network requirements for a Generic KMIP integration.

Prepare the CryptoHub service, the KMIP application, the network path, and protected storage for the endpoint TLS files before you configure the integration.

## Supported versions

Use the following versions for this guide:

| Component | Version |
| - | - |
| CryptoHub | 7.3.0.x, build 7.3.0.0b or later in that branch |
| KMIP application | Any application with a KMIP client that supports TLS 1.2 or later with client-certificate authentication |
| Optional test client | PyKMIP 0.11.0 on Python 3.8 through 3.13 |

KMIP is a network protocol, so the application host can run any operating system that the application supports. No Futurex software is installed on the application host.

## Required access

* Obtain two CryptoHub administrator identities. Dual control protects service and endpoint deployment.
* Obtain administrative access to the application's key-management or external key manager settings. Most applications restrict KMIP server configuration to administrators.
* Prepare a protected location for the endpoint download. It contains the client private key and the password for the PKCS #12 file.

## Network and TLS

* Allow outbound TCP 5696 from the application host to the CryptoHub FQDN. TCP 5696 is the KMIP port.
* Allow administrators to reach the CryptoHub web interface on TCP 443. The application itself does not use TCP 443.
* Configure DNS so the CryptoHub FQDN resolves from the application host.
* Keep server certificate verification enabled in the application's KMIP settings.
* The KMIP port accepts TLS 1.2 and TLS 1.3 and uses the TLS extended master secret extension.

<Warning>
  TLS inspection terminates the connection before it reaches CryptoHub and breaks mutual TLS. Exempt the CryptoHub FQDN and TCP 5696 from TLS inspection.
</Warning>

## Application requirements

* Identify the application's KMIP settings. Record the fields it requires for the server address, port, client certificate, client private key, server CA, and optional username and password.
* Identify the certificate format the application accepts, for example separate PEM files, a combined PEM file, or a PKCS #12 file.
* Identify whether the application requires an RSA or ECC client certificate. The endpoint dialog creates either type.
* Identify whether the application retrieves key material or requests server-side operations.
