- Log in to the HSM.
- Create a new key pair on the Vectera Plus.
- Generate a CSR from that key pair.
- Create a CA
- Sign the CSR by using a CA that you also create on the HSM.
Log in to the HSM
Perform the following steps to connect and log in to the HSM through FXCLI:Configure TLS certificates for communication between FXCLI and the HSM by using the
tls set of commands.Run
tls help to access syntax documentation.Create a key pair
Perform the following steps to create a new key pair on the Vectera Plus:Create a new key pair in the next available key slot on the HSM, modifying the key usage values to match your specific requirements:
FXCLI
Generate a CSR
Perform the following steps to generate a CSR:Create a Certificate Authority
Perform the following steps to create a Certificate Authority:Create a certificate from the new key pair that you created:
FXCLI
Note that the CA certificate was output to a file called
Ca.pem.
