Generic
Generic Futurex PKCS #11 (FXPK...

Configure the KMES Series 3

13min

This section starts with general configurations you must make on the to allow the PKCS #11 module to integrate with the and then covers the steps required to configure TLS communication between the and the PKCS #11 library.

General KMES configurations

Perform the tasks in this section to configure the for this integration.

Create a role and identity for Futurex PKCS #11 with the required permissions

Perform the following steps to create a new role and identity for PKCS #11 (FXPKCS11) on the :

A later section shows you how to configure the identity name and password inside of the PKCS #11 configuration file.

1

Log in to the application interface with the default Admin identities.

2

Go to Identity Management > Roles, and select [ Add ].

3

In the Role Editor window, specify a Name for the role and set the number of logins required to 1. Then, go to the Advanced tab and allow authentication to the Host API port only. Leave all other fields set to the default values.

4

Go to the Permissions tab and select the All profile to enable all permissions.

We usually do not recommend enabling all permissions, but in the case of the Generic FXPKCS11 integration guide, the application being integrated is unknown; therefore, the required permissions are also unknown.

5

Select [ OK ] to finish creating the role.

6

Go to Identity Management > Identities, right-click anywhere in the window, and select Add > Client Application.

7

In the Info tab of the Identity Editor window, select Application for the storage location and specify a Name for the identity, such as crypto1.

8

In the Assigned Roles tab, select the role you created in the previous section.

9

Under Authentication, select the API Key mechanism and then [ Remove ]. Then, select [ Add ] and set the type to Password. Set the password for the identity and then select [ OK ] to finish.

A later section shows you how to configure the password in the Futurex PKCS #11 configuration file.

10

Select [ OK ] to finish creating the identity.

Enable the Host API commands required for PKCS #11

Because the PKCS #11 library connects to the Host API port on the , you must define which Host API commands to enable for execution by the FXPKCS11 library. To set the allowed commands, complete the following steps:

1

Log in to the application interface with the default Admin identities.

2

Go to Administration > Configuration > Host API Options and select the All preset to enable all commands, then select [ Save ].

We usually do not recommend enabling all commands, but in the case of the Generic FXPKCS11 integration guide, the application being integrated is unknown; therefore, the required commands are also unknown.

Configure TLS communication between the KMES Series 3 and the Futurex PKCS #11 module

Perform the following tasks to configure TLS communications.

Create a Certificate Authority (CA)

1

Log in to the application interface with the default Admin identities.

2

Select PKI > Certificate Authorities in the left-side menu, and select [ Add CA ] at the bottom of the page.

3

In the Certificate Authority window, enter a Name for the certificate container, leave all other fields set to the default values, and select [ OK ].

The certificate container you created now displays in the Certificate Authorities menu.

4

Right-click on the certificate container and select Add Certificate > New Certificate.

5

In the Subject DN tab, set a Common Name for the certificate, such as System TLS CA Root.

6

In the Basic Info tab, leave all fields set to the default values.

7

In the V3 Extensions tab, select the Certificate Authority profile, and select [ OK ].

The root CA certificate now displays under the previously created certificate container.

Generate a CSR for the System/Host API connection pair

1

Go to Administration > Configuration > Network Options.

2

In the Network Options window, go to the TLS/SSL Settings tab.

3

Under the System/Host API connection pair, uncheck Use Futurex certificates, and select [ Edit ] next to PKI Keys in the User Certificates section.

4

In the Application Public Keys window, select [ Generate ].

5

When prompted that SSL will not be functional until new certificates are imported, select [ Yes ] to continue.

6

In the PKI Parameters window, leave the fields set to the default values and select [ OK ].

You see that a PKI Key Pair is loaded in the Application Public Keys window.

7

Select [ Request ].

8

In the Subject DN tab, set a Common Name for the certificate, such as KMES.

9

In the V3 Extensions tab, select the TLS Server Certificate profile.

10

In the PKCS #10 Info tab, select a save location for the CSR, and select [ OK ].

11

When prompted that the certificate signing request was successfully written to the file location that was selected, select [ OK ].

12

Select [ OK ] again to save the Application Public Keys settings.

The main Network Options window shows Loaded next to PKI Keys for the System/Host API connection pair.

Sign the System/Host API CSR

1

Go to PKI > Certificate Authorities.

2

Right-click on the root CA certificate you created for this integration, and select Add Certificate > From Request.

3

In the file browser, find and select the CSR generated for the System/Host API connection pair.

4

After it loads, you don't need to modify any settings for the certificate. Select [ OK ].

The signed System/Host API certificate now shows under the root CA certificate on the Certificate Authorities page.

Export the Root CA certificate

1

Go to PKI > Certificate Authorities.

2

Right-click the System TLS CA Root certificate, then select Export > Certificate(s).

3

In the Export Certificate window, change the encoding to PEM, and select [ Browse ].

4

In the file browser, go to the location where you want to save the Root CA certificate. Specify a name for the file, and select [ Open ].

5

Select [ OK ].

Export the signed System/Host API certificate

1

Go to PKI > Certificate Authorities.

2

Right-click the certificate, then select Export > Certificate(s).

3

In the Export Certificate window, change the encoding to PEM and select [ Browse ].

4

In the file browser, navigate to the location where you want to save the signed System/Host API certificate. Specify a name for the file, then select [ Open ].

5

Select [ OK ]. A message box will pop up stating that the PEM file was successfully written to the location that you specified.

A message box shows that the PEM file was successfully written to the location that you specified.

Load the exported certificates into the System/Host API connection pair

1

Go to Administration > Configuration > Network Options.

2

In the Network Options window, go to the TLS/SSL Settings tab.

3

Select [ Edit ] next to Certificates in the User Certificates section.

4

Right-click on the System/Host API SSL CA X.509 certificate container, and select [ Import ].

5

Select [ Add ] at the bottom of the Import Certificates window.

6

In the file browser, select both the root CA certificate and the signed System/Host API certificate, and select [ Open ].

The certificate chain appears in the Verified section of the window.

7

Select [ OK ] to save the changes.

In the Network Options window, the System/Host API connection pair now shows Signed loaded next to Certificates in the User Certificates section.

Issue a client certificate for the Futurex PKCS #11 module

A later section shows you how to configure the client certificate created here inside the PKCS #11 configuration file.

1

Go to PKI > Certificate Authorities.

2

Right-click the System TLS CA Root certificate and select Add Certificate > New Certificate.

3

In the Subject DN tab, set a Common Name for the certificate.

4

Leave all fields in the Basic Info tab set to the default values.

5

In the V3 Extensions tab, select the TLS Client Certificate profile, and select [ OK ].

The PKCS #11 client certificate now displays under the System TLS CA Root certificate.

Export the client certificate as a PKCS #12 file

To perform the following steps, you must go to Administration > Configuration > Options and enable the Allow export of certificates using password option.

1

Go to PKI > Certificate Authorities.

2

Right-click the PKCS #11 client certificate, and select Export > PKCS12.

3

Set a PKCS #12 password, leave Export Selected Certificate with Parents selected, then select [ Next ].

4

Select the storage device to use and select [ OK ].

5

Enter a name for the file, select the location where you want to save it, and select [ Open ].

You must move the FXPKCS11 Client certificate to the computer where you installed the PKCS #11 module. A later section shows you how to configure it inside the FXPKCS11 configuration file and use it for TLS communication with the .