Install FXPKCS11 on the same computer as OpenVPN Access Server.
1
Download the Futurex PKCS #11 tarball for Linux from the Futurex Portal.
2
Extract the tarball into The
/usr/local/lib, which creates the /usr/local/lib/fxpkcs11 directory:Shell
For the Futurex PKCS #11 module to be accessible system-wide, an administrative user must extract it into
/usr/local/lib. If only the current user needs to use the module, extract it into $HOME/.local/lib instead and adjust the paths in the following steps.fxpkcs11 directory contains the following files and directories:Each OpenSSL directory contains
libfxpkcs11.so (the PKCS #11 library), configTest (tests the configuration and connection to the HSM), and PKCS11Manager (tests the connection and manages the HSM through the library).3
Check which OpenSSL branch the computer uses:For example,
Shell
OpenSSL 3.0.13 means you use the OpenSSL-3.x build. Ubuntu 22.04 and later and RHEL 9 and later use OpenSSL 3.x.4
Copy the matching build into
/usr/local/lib/fxpkcs11 so that the library path is /usr/local/lib/fxpkcs11/libfxpkcs11.so. The following example copies the 64-bit OpenSSL 3.x build:Shell
5
Copy the configuration file to
/etc, the default location where the library looks for it:Shell
To keep the configuration file somewhere else, set the
FXPKCS11_CFG environment variable to its full path for every process that loads the library, including configTest and PKCS11Manager.
