Skip to main content
Register CryptoHub as a PKCS #11 crypto source in ADSS Server. This enables ADSS to use CryptoHub-backed keys for signing operations.
1

Open the ADSS Admin Console

Navigate to the ADSS Admin Console (default: https://<host>:8774/adss/console) and log in with administrator credentials.
2

Navigate to Crypto Sources

Go to Key Manager > Crypto Sources.
3

Add a new PKCS #11 crypto source

Click New.
4

Configure the crypto source

Enter the following settings:
5

Fetch Slots

Click Fetch Slots.
6

Define the PKCS#11 slot and PIN

Enter the following settings:
The PIN value corresponds to the <CRYPTO-OPR-PASS> parameter in the fxpkcs11.cfg file included in the endpoint package.
7

Test the connection

Click Test Connection. You should see, “Connection with the PKCS#11 module is successful”.
8

Save the configuration

Click Save. You must restart all instances in Server Manager to make the changes take effect.
9

Restart instances and services

Go to Server Manager and click Restart All Instances. Then restart the ADSS Windows Services or Unix Daemons. Adding a new PKCS #11 module requires a full service restart, not just an instance restart.
10

Verify the PKCS#11 crypto source is available

Go to Key Manager > Crypto Sources and verify that the status for the PKCS#11 crypto source is showing as Available.