You can complete most tasks in this section by using either Excrypt Manager or FXCLI. The exception is the second option of task 7 (Create connection certificates for mutual authentication), for which you must use FXCLI.You can optionally complete steps 4 through 6 by using the Guardian Series 3. Refer to the applicable guide for configuring HSMs for PKCS #11 integrations by using the Guardian Series 3.
If you use a virtual HSM for the integration, you must connect to it over the network through FXCLI, the Excrypt Touch, or the Guardian Series 3.
- Connect to the HSM through the front USB port by using Excrypt Manager or FXCLI.
- Validate the enabled features on the HSM.
- Set up the network configuration.
- Load the FTK, PMK, and BEK major keys.
- Configure a transaction processing connection.
- Create a new application partition for the integration.
- Create a new identity that has access to the new application partition.
- Configure TLS Authentication by using one of the following options:
- Enable server-side authentication.
- Create client certificates for mutual authentication.
- Enable the EDSVWU multi-usage combination for asymmetric keys.

