For this step, you must log in with an Identity that has a role with the Keys:All Slots permission. You can use the default Administrator role and Admin identities.
The Futurex CNG library enables Windows to associate an Access Control List (ACL) with an HSM key slot. Windows updates this ACL during key pair generation and permission updates. To lock the ACL from changing, perform the following steps:
1
Connect the Excrypt Manager application to the Vectera Plus HSM.
2
Log in under dual control.
3
Go to the KeyManagement page
4
Select EditKeyStorage.
5
Locate the board slot containing the CNG private key. The CNG provider logs this information during key pair generation.
Use the following command to view the CA certificate store. The LDAP URI varies depending on your organizational Active Directory domain (for example, fx.futurex.com) and CA name (for example, fx-FXCA).
The following steps demonstrate one way to test using the HSM to sign a certificate for the CA server.
1
Open the CertificateManager on the CA server
2
Right-click Personal > AllTasks > Request New Certificate.
3
In the CertificateEnrollment window, select [ Next ].
4
On the CertificateEnrollmentPolicy page, choose a certificate enrollment service associated with the CA server, such as Active Directory Enrollment Policy for an Enterprise CA. Select [ Next ].
5
On the RequestCertificates page, choose a certificate template and select [ Enroll ].
If the HSM connects, a success message displays.If the HSM is offline, you get an error.
6
To locate the issued certificate, perform the following steps:
Open the Active Directory Certificate Authority tool from the Server Manager.
Expand the node associated with your CA common name.
Select IssuedCertificates.
A certificate matching your request should display on this page.