Skip to main content
Verify your environment meets these requirements.

Supported hardware

  • KMES Series 3, application version 6.3.1.3 or later, with initial setup completed (including loading a Platform Master Key and network configuration).

Supported operating systems

  • Windows 10 or later

Required access

  • An account on the KMES with administrator permissions to create roles, identities, TLS PKI, and update system settings.
  • Local administrator/root access on the Windows machine where SignTool is installed.

Network and firewall

  • Allow outbound TCP port 2001(default Host API port) from the Windows client machine to the KMES Series 3, specified by FQDN (for example, kmes.example.com) or CIDR (for example, 10.0.0.0/24).
TLS inspection or SSL proxies can break mutual TLS handshakes. Exempt the KMES FQDN(s) from inspection. Configure the KMES Series 3 with an FQDN so the exemption applies.

Other

  • OpenSSL
  • Microsoft SignTool
SignTool is available as part of the Windows SDK, which you can download from https://developer.microsoft.com/windows/downloads/windows-10-sdk/.