Skip to main content
Verify your environment meets these requirements.

Supported hardware

  • Excrypt HSM (formerly Vectera Plus), firmware 7.2.x.x or later.

Supported operating systems

  • Windows 10 or later
  • Linux with OpenSSL 1.0.x, 1.1.x, or 3.x. The Futurex PKCS #11 package includes a build for each OpenSSL branch; use the build that matches the OpenSSL version on the computer (openssl version). The 64-bit (x64) builds cover all three branches; the 32-bit (x86) builds cover only OpenSSL 1.0.x and 1.1.x.

Required access

  • Both default administrator identities (Admin1 and Admin2), or two identities with equivalent permissions. Creating application partitions and identities requires dual control, so both must log in.
  • Local administrator/root privileges on the computer where Java Jarsigner is installed.

Network and firewall

  • Allow outbound TCP port 9100 (default Excrypt port) from the computer running Java Jarsigner to the Excrypt HSM, specified by FQDN (for example, hsm.example.com) or CIDR (for example, 10.0.0.0/24).
  • If you configure the HSM over the network with FXCLI or Excrypt Manager, allow TCP port 9009 (default admin port) from that workstation to the HSM. Administrator logins work only on the admin port.
TLS inspection or SSL proxies can break mutual TLS handshakes. Exempt the Excrypt HSM FQDNs from inspection. Configure the HSM with an FQDN so the exemption applies.

Other

  • OpenSSL, to create the client TLS key and certificate signing request.
  • Oracle Java 11, 17, or 21
To ensure proper compatibility between Java SunPKCS11 and the Futurex PKCS #11 module, you must use Oracle Java instead of OpenJDK. Futurex supports Oracle Java 11, 17, and 21.