Skip to main content
Register the Futurex Vectera Plus as a PKCS #11 crypto source in ADSS Server.
1

Open the ADSS Admin Console

Navigate to the ADSS Admin Console (default: https://<host>:8774/adss/console) and log in with administrator credentials.
2

Navigate to Crypto Sources

Go to Key Manager > Crypto Sources.
3

Add a new PKCS #11 crypto source

Click New.
4

Configure the crypto source

Enter the following settings:
SettingValue
StatusSelect Active
Friendly NameA descriptive name (e.g., Futurex HSM)
Crypto Source VendorSelect Other
Interface TypeSelect PKCS#11
PKCS#11 ModulePath to the FxPKCS11 library file (e.g., /usr/local/lib/fxpkcs11/libfxpkcs11.so)
5

Fetch Slots

Click Fetch Slots.
6

Define the PKCS#11 slot and PIN

Enter the following settings:
SettingValue
PKCS#11 SlotSelect 0
PKCS#11 PINEnter the password for the identity you defined in the FxPKCS11 configuration file
PKCS#11 Connection Pool SizeUse the default value of 30
PKCS#11 Monitoring IntervalUse the default value of 360
Enable FIPS modeLeave the box unchecked unless you need to use FIPS mode
Copy certificates to deviceLeave the box unchecked
Key TemplateSelect Default PKCS#11 Key Template
Key WrappingSelect No key wrapping
7

Test the connection

Click Test Connection. You should see, “Connection with the PKCS#11 module is successful”.
8

Save the configuration

Click Save. You must restart all instances in Server Manager to make the changes take effect.
9

Restart instances and services

Go to Server Manager and click Restart All Instances. Then restart the ADSS Windows Services or Unix Daemons. Adding a new PKCS #11 module requires a full service restart, not just an instance restart.
10

Verify the PKCS#11 crypto source is available

Go to Key Manager > Crypto Sources and verify that the status for the PKCS#11 crypto source is showing as Available.