Verify your environment meets these requirements.
Supported hardware
- Excrypt HSM (formerly Vectera Plus), firmware
7.2.x.x or later.
Supported operating systems
- Linux. The Futurex PKCS #11 package includes a build for each OpenSSL branch (1.0.x, 1.1.x, and 3.x); use the build that matches the OpenSSL version on the computer (
openssl version).
Required access
- Both default administrator identities (Admin1 and Admin2), or two identities with equivalent permissions. Creating application partitions and identities requires dual control, so both must log in.
- Local administrator/root privileges on the computer where BIND is installed.
Network and firewall
- Allow outbound TCP port 9100 (default Excrypt port) from the computer running BIND to the Excrypt HSM, specified by FQDN (for example,
hsm.example.com) or CIDR (for example, 10.0.0.0/24).
- If you configure the HSM over the network with FXCLI or Excrypt Manager, allow TCP port 9009 (default admin port) from that workstation to the HSM. Administrator logins work only on the admin port.
TLS inspection or SSL proxies can break mutual TLS handshakes. Exempt the Excrypt HSM FQDNs from inspection. Configure the HSM with an FQDN so the exemption applies.
Other
- OpenSSL (v3.0.0 or newer)
- BIND (v9.20 or newer)
You must compile BIND from source to work with Futurex HSMs. Using package managers to install BIND might cause linking issues between bind9-utils and OpenSSL providers.