Skip to main content
Install FXPKCS11 on the same computer as the application that uses the OpenSSL pkcs11-provider.
Perform the following steps to install Futurex PKCS #11:
1
Download the Futurex PKCS #11 tarball for Linux from the Futurex Portal.
2
Extract the tarball into /usr/local/lib, which creates the /usr/local/lib/fxpkcs11 directory:
Shell
For the Futurex PKCS #11 module to be accessible system-wide, an administrative user must extract it into /usr/local/lib. If only the current user needs to use the module, extract it into $HOME/.local/lib instead and adjust the paths in the following steps.
The fxpkcs11 directory contains the following files and directories:Each OpenSSL directory contains libfxpkcs11.so (the PKCS #11 library), configTest (tests the configuration and connection to the HSM), and PKCS11Manager (tests the connection and manages the HSM through the library).
3
Check which OpenSSL branch the computer uses:
Shell
For example, OpenSSL 3.0.13 means you use the OpenSSL-3.x build. Ubuntu 22.04 and later and RHEL 9 and later use OpenSSL 3.x.
4
Copy the matching build into /usr/local/lib/fxpkcs11 so that the library path is /usr/local/lib/fxpkcs11/libfxpkcs11.so. The following example copies the 64-bit OpenSSL 3.x build:
Shell
5
Copy the configuration file to /etc, the default location where the library looks for it:
Shell
To keep the configuration file somewhere else, set the FXPKCS11_CFG environment variable to its full path for every process that loads the library, including configTest and PKCS11Manager.

Java and OpenSSL

If you plan to install Java and OpenSSL on the same system, see Using OpenSSL and Java.