You can complete most tasks in this section by using either Excrypt Manager or FXCLI. To create client certificates for mutual authentication (task 8, second option), you must use FXCLI.You can optionally complete tasks 4 through 7 by using the Guardian Series 3. For details, see Guardian Series 3: Configure HSMs for PKCS #11 integrations.
If you use a virtual HSM, you can’t use the front USB port. Connect to it over the network through FXCLI (admin port 9009), the Excrypt Touch, or the Guardian Series 3.
- Connect to the HSM through the front USB port by using Excrypt Manager or FXCLI.
- Validate the enabled features on the HSM.
- Set up the network configuration.
- Load the FTK and PMK major keys, and optionally the BEK.
- Configure the transaction processing connection.
- Create an application partition for the integration.
- Create an identity that has access to the new application partition.
- Configure TLS authentication by using one of the following options:
- Enable server-side authentication.
- Create client certificates for mutual authentication.

