Skip to main content
Install FXPKCS11 on the same computer as NGINX.
Perform the following steps to install Futurex PKCS #11:
1
Download the Futurex PKCS #11 tarball for Linux from the Futurex Portal.
2
Extract the tarball into /usr/local/lib, which creates the /usr/local/lib/fxpkcs11 directory:
Shell
For the Futurex PKCS #11 module to be accessible system-wide, an administrative user must extract it into /usr/local/lib. If only the current user needs to use the module, extract it into $HOME/.local/lib instead and adjust the paths in the following steps.
The fxpkcs11 directory contains the following files and directories:Each OpenSSL directory contains libfxpkcs11.so (the PKCS #11 library), configTest (tests the configuration and connection to the HSM), and PKCS11Manager (tests the connection and manages the HSM through the library).
3
Check which OpenSSL branch the computer uses:
Shell
For example, OpenSSL 3.0.13 means you use the OpenSSL-3.x build. Ubuntu 22.04 and later and RHEL 9 and later use OpenSSL 3.x.
4
Copy the matching build into /usr/local/lib/fxpkcs11 so that the library path is /usr/local/lib/fxpkcs11/libfxpkcs11.so. The following example copies the 64-bit OpenSSL 3.x build:
Shell
5
Copy the configuration file to /etc, the default location where the library looks for it:
Shell
To keep the configuration file somewhere else, set the FXPKCS11_CFG environment variable to its full path for every process that loads the library, including configTest and PKCS11Manager.