- Log in to the HSM.
- Create a new key pair on the Vectera Plus.
- Generate a CSR from that key pair.
- Create a CA
- Sign the CSR by using a CA that you also create on the HSM.
Log in to the HSM
Perform the following steps to connect and log in to the HSM through FXCLI:1
Run the FXCLI application.
2
Configure TLS certificates for communication between FXCLI and the HSM by using the
tls set of commands.Run
tls help to access syntax documentation.3
Connect to the HSM by using the following command:
FXCLI
4
Log in to the HSM with the default Admin1 and Admin2 identities by running the following command twice (entering the username and password when prompted):
FXCLI
Create a key pair
Perform the following steps to create a new key pair on the Vectera Plus:1
Create a new key pair in the next available key slot on the HSM, modifying the key usage values to match your specific requirements:
FXCLI
2
Confirm which key slot the private key was added to:
FXCLI
3
Assign a PKCS11 label to the key (certutil needs you to set this external data field so that it can find the key in a later section):
The PKCS11 label value should match the name that was set for the key pair in the generate command.
FXCLI
Generate a CSR
Perform the following steps to generate a CSR:1
Generate a CSR from the new key pair that was created:
FXCLI
Create a Certificate Authority
Perform the following steps to create a Certificate Authority:1
Create a new key pair in the next available key slot on the HSM:
FXCLI
2
Create a certificate from the new key pair that you created:
FXCLI
Note that the CA certificate was output to a file called
Ca.pem.3
Confirm which key slot the private key was added to:
FXCLI
4
Assign a PKCS11 label to the key (certutil needs you to set this external data field so that it can find the key in a later section):
The PKCS11 label value should match the name that was set for the key pair in the generate command.
FXCLI
Sign the CSR
Perform the following steps to sign the CSR by using the Certificate Authority:1
Sign the CSR with the CA you just created, modifying the key usage values to match your specific certificate requirements:
FXCLI
Note that the signed leaf certificate was output to a file called
IgDemo.pem.
