Skip to main content
These steps are typically performed by the OpenVPN Connect User. See Underlying Responsibility Roles for more information.
In this section, we’ll configure OpenVPN Connect to use the Futurex PKCS #11 module and CryptoHub as a hardware (HW) token. The .ovpn client profile and HW token password are required to complete these steps. If you do not have them, refer to the [Download the client connection profile (.ovpn file)] (./Download_the_client_connection_profile_(.ovpn_file)) section or contact the Access Server Admin to obtain them.

Assign an external certificate to the profile

1
Locate your VPN client profile (.ovpn file) and the HW token password.
2
Shut down OpenVPN Connect if it’s running.
3
Launch OpenVPN Connect.
4
If it is your first time uploading a profile, select [ Upload File ] near the bottom of the OpenVPN Connect application.If you have previously uploaded a profile, select the Menu button (3 lines in the top left corner) > My Profiles > the [ + ] blue box near the bottom right > [ Upload File ] near the bottom.
5
Select the Menu button (3 lines in the top left corner) > My Profiles.
6
Click the pencil icon on your newly imported profile.
7
Under Certificates, click [ Select ].
8
Under Hardware Tokens, select the CryptoHub from the list and click [ Authorize ].
It will be named something similar to “HSM 1830884596”.
9
Enter the HW token password in the Pin text field and select [ Enter ].
10
After successful authorization, select your personal certificate and private key from the list and click [ Select ].
Only select your personal client certificate and private key. Do not select the CA certificate. If you are unsure which one is yours, it will typically be identified by your username or the name assigned by your administrator — not by the CA name (e.g., Futurex_CA).
11
Click on [ Save Changes ] to save the profile configuration.

Connect with a profile and the hardware token

Now that you have the HSM-stored certificate and key assigned to the profile, let’s test the VPN connection.
1
Under the Futurex profile, click on [ Connect ].
2
Enter the hardware token password in the Pin text field and click [ Enter ].
3
After a successful connection, OpenVPN Connect displays connection statistics.