Verify your environment meets these requirements.
Supported hardware
- Excrypt HSM (formerly Vectera Plus), firmware
7.2.x.x or later.
Supported operating systems
Required access
- Both default administrator identities (Admin1 and Admin2), or two identities with equivalent permissions. Creating application partitions and identities requires dual control, so both must log in.
- Salesforce
- Enterprise, Performance, and Unlimited editions with
Salesforce Shield or Shield Platform Encryption licenses
- Developer editions available for free
- Salesforce account with the following permissions:
- Manage Encryption Keys
- Manage Certificates
- Customize Application
Network and firewall
- Allow outbound TCP port 9100 (default Excrypt port) from the computer that connects to the Excrypt HSM, specified by FQDN (for example,
hsm.example.com) or CIDR (for example, 10.0.0.0/24).
- If you configure the HSM over the network with FXCLI or Excrypt Manager, allow TCP port 9009 (default admin port) from that workstation to the HSM. Administrator logins work only on the admin port.
TLS inspection or SSL proxies can break mutual TLS handshakes. Exempt the Excrypt HSM FQDNs from inspection. Configure the HSM with an FQDN so the exemption applies.
Other