Security User Guide: Intel® Programmable Acceleration Card with Intel® Arria® 10 GX FPGA
                    
                        ID
                        683453
                    
                
                
                    Date
                    3/06/2020
                
                
                    Public
                
            
                        
                        
                            
                            
                                3.1. Installing PACSign
                            
                        
                            
                            
                                3.2. PACSign Tool
                            
                        
                            
                            
                                3.3. Creating Unsigned Images
                            
                        
                            
                            
                                3.4. Using an HSM Manager
                            
                        
                            
                                3.5. Creating Keys
                            
                            
                        
                            
                            
                                3.6. Root Entry Hash Bitstream Creation
                            
                        
                            
                                3.7. Signing Images
                            
                            
                        
                            
                            
                                3.8. Creating a CSK ID Cancellation Bitstream
                            
                        
                            
                            
                                3.9. PACSign PKCS11 Manager *.json Reference
                            
                        
                            
                                3.10. Creating a Custom HSM Manager
                            
                            
                        
                            
                            
                                3.11. PACSign Man Page
                            
                        
                    
                3.4. Using an HSM Manager
    The PACSign tool does not implement any cryptographic functions. PACSign must interact with a cryptographic service, and it does this through modules called Hardware Security Module (HSM) managers. PACSign provides the following managers: 
    
 
  - openssl_manager: interfaces with OpenSSL
- pkcs11_manager: interfaces with any HSM implementing PKCS#11
   Related Information