Verify your environment meets these requirements.
Supported hardware
- Excrypt HSM (formerly Vectera Plus), firmware
7.2.x.x or later.
Supported operating systems
- Linux with OpenSSL 1.0.x, 1.1.x, or 3.x. The Futurex PKCS #11 package includes a build for each OpenSSL branch; use the build that matches the OpenSSL version on the computer (
openssl version). The 64-bit (x64) builds cover all three branches; the 32-bit (x86) builds cover only OpenSSL 1.0.x and 1.1.x.
Required access
- Both default administrator identities (Admin1 and Admin2), or two identities with equivalent permissions. Creating application partitions and identities requires dual control, so both must log in.
- Local administrator/root privileges on the computer where Curity Identity Server is installed.
Network and firewall
- Allow outbound TCP port 9100 (default Excrypt port) from the computer running Curity Identity Server to the Excrypt HSM, specified by FQDN (for example,
hsm.example.com) or CIDR (for example, 10.0.0.0/24).
- If you configure the HSM over the network with FXCLI or Excrypt Manager, allow TCP port 9009 (default admin port) from that workstation to the HSM. Administrator logins work only on the admin port.
TLS inspection or SSL proxies can break mutual TLS handshakes. Exempt the Excrypt HSM FQDNs from inspection. Configure the HSM with an FQDN so the exemption applies.
Other
- OpenSSL, to create the client TLS key and certificate signing request.
- Java 17 or 21
- Curity Identity Server