> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenSSL Provider

> Conceptual overview of using Futurex KMES with OpenSSL providers instead of engines, including rationale and design choices.

This document provides information on configuring Futurex KMES Series 3 with OpenSSL providers using PKCS #11 libraries. For additional questions related to your HSM, see the relevant administrator guide.

## Application description

From the main **Latchset - pkcs11-provider** on GitHub ([**https://github.com/latchset/pkcs11-provider)**](https://github.com/latchset/pkcs11-provider):

This is an OpenSSL 3.x provider to access Hardware and Software Tokens using the PKCS#11 Cryptographic Token Interface. Access to tokens depends on loading an appropriate PKCS#11 driver that knows how to talk to the specific token. The PKCS#11 provider is a connector that allows OpenSSL to make proper use of such drivers. This code targets PKCS#11 version 3.1 but is backwards compatible to version 3.0 and 2.40 as well.

## Why providers instead of engines

OpenSSL 3.x introduced a **provider-based architecture**, replacing the old **engine system** from OpenSSL 1.x

<table>
  <thead>
    <tr>
      <th>Feature</th>
      <th>OpenSSL 1.x Engine</th>
      <th>OpenSSL 3.x Provider</th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>Integration</td>
      <td>Manual registration, limited API support</td>
      <td>Natively integrated, modular, supports OpenSSL 3.x API</td>
    </tr>

    <tr>
      <td>Hardware Access</td>
      <td>Requires engine-specific code</td>
      <td>Provides standardized PKCS#11 module access</td>
    </tr>

    <tr>
      <td>Flexibility</td>
      <td>Harder to maintain or extend</td>
      <td>Easier to extend, multiple providers can coexist</td>
    </tr>
  </tbody>
</table>

In short: providers are **modern, modular, and fully supported,** making them the preferred method for PKCS#11 HSM integration.

## Why Latchset pkcs11-provider

* Direct integration with OpenSSL 3.x provider API
* Variety of successful integrations tested with Futurex HSMs
* Supports PKCS#11 3.0+ tokens without extra libraries
* Simplifies configuration compared to engines
