Install FXPKCS11 on the same computer as the application for the integration.
Windows
Perform the following steps to install Futurex PKCS #11 in Windows:1
In a Windows environment, the easiest way to install the Futurex PKCS #11 module is to download FXTools from the Futurex Portal and install it.
2
After you download FXTools, run the installer as an administrator.
3
By default, the system installs all tools. You can overwrite and choose not to install the following modules:
| Module | Description |
|---|---|
| Futurex Client Tools | Command Line Interface (CLI) and associated SDK for both Java and C. |
| Futurex CNG Module | The Microsoft Next Generation Cryptographic Library. |
| Futurex Cryptographic Service Provider (CSP) | The Legacy Microsoft Cryptographic Library. |
| Futurex EKM Module | The Microsoft Enterprise Key Management library. |
| Futurex PKCS #11 Module | The Futurex PKCS #11 library and associated tools. |
| Futurex Secure Access Client | The Client that connects a Futurex Excrypt Touch to a local laptop with a USB or to a remote Futurex device. |
4
After starting the installation, the system installs all noted services. If you selected the Futurex Secure Access Client, the Excrypt Touch driver is also installed and might start minimized or in the background.
The installation installs all services in the
C:\Program Files\Futurex directory. The CNG Module, CSP Module, EKM Module, and PKCS #11 Module all require configuration files, located in their corresponding directory with a .cfg extension.Linux
Perform the following steps to install Futurex PKCS #11 in Linux:1
Download the Futurex PKCS #11 tarball for Linux from the Futurex Portal.
2
Extract the tarball into The
/usr/local/lib, which creates the /usr/local/lib/fxpkcs11 directory:Shell
For the Futurex PKCS #11 module to be accessible system-wide, an administrative user must extract it into
/usr/local/lib. If only the current user needs to use the module, extract it into $HOME/.local/lib instead and adjust the paths in the following steps.fxpkcs11 directory contains the following files and directories:Each OpenSSL directory contains
libfxpkcs11.so (the PKCS #11 library), configTest (tests the configuration and connection to the HSM), and PKCS11Manager (tests the connection and manages the HSM through the library).3
Check which OpenSSL branch the computer uses:For example,
Shell
OpenSSL 3.0.13 means you use the OpenSSL-3.x build. Ubuntu 22.04 and later and RHEL 9 and later use OpenSSL 3.x.4
Copy the matching build into
/usr/local/lib/fxpkcs11 so that the library path is /usr/local/lib/fxpkcs11/libfxpkcs11.so. The following example copies the 64-bit OpenSSL 3.x build:Shell
5
Copy the configuration file to
/etc, the default location where the library looks for it:Shell
To keep the configuration file somewhere else, set the
FXPKCS11_CFG environment variable to its full path for every process that loads the library, including configTest and PKCS11Manager.
