Integrare¶
Acest capitol descrie cum să integrați NetHSM în aplicații și cum să testați această integrare. Dacă sunteți în căutarea unui software care se integrează deja bine cu NetHSM, iată o listă de software compatibil.
REST-API¶
Interfața principală a NetHSM este o interfață REST-API modernă care garantează cea mai bună performanță și funcționalitate. Specificația API este disponibilă în formatul OpenAPI, și poate fi inspectată și testată în browserul API ` <https://nethsmdemo.nitrokey.com/api_docs/index.html>`_ .
PKCS#11¶
The NetHSM supports the PKCS#11 standard. The required driver is available from the repository. The repository contains the source code and libraries, for different operating systems. The PKCS#11 guide describes the usage in detail.
Dezvoltare și testare¶
Instanță demo¶
A public NetHSM demo instance is available at nethsmdemo.nitrokey.com.
It will be reset every eight hours (CET 6:00, 14:00, 22:00). User admin, password adminadmin, unlock password unlockunlock.
Imaginea containerului¶
NetHSM imagini container sunt disponibile pentru testare și producție.
Integrarea în aplicația personalizată¶
To integrate the NetHSM into own custom applications, client libraries are available for almost all programming languages. Here are our libraries for Python and Rust as well as 3rd party Rust crate and Go library. For all other programming languages we recommend using OpenAPI Generator.
Lista tuturor limbilor disponibile poate fi consultată după cum urmează.
$ docker run --rm -ti openapitools/openapi-generator-cli list -i stable
$ podman run --rm -ti openapitools/openapi-generator-cli list -i stable
Clientul NetHSM poate fi generat pentru limbajul dumneavoastră de programare după cum urmează.
$ docker run --rm -ti -v "${PWD}/out:/out" openapitools/openapi-generator-cli generate -i=https://nethsmdemo.nitrokey.com/api_docs/nethsm-api.yaml -o out -g javascript
$ podman run --rm -ti -v "${PWD}/out:/out" openapitools/openapi-generator-cli generate -i=https://nethsmdemo.nitrokey.com/api_docs/nethsm-api.yaml -o out -g javascript
Codul generat de client, în acest exemplu JavaScript, va fi creat în directorul ./out/. Acest director conține, de asemenea, documentația necesară modului de utilizare.
Important
If Podman is used with enforcing SELinux, a labeling to the volume mount might be required.
The mode of SELinux can be requested with sestatus |grep "Current mode".
If the mode is set to enforcing, a change to the context is required.
In this case the volume mount must be suffixed with :z, resulting in -v "${PWD}/out:/out:z".
Interfața liniei de comandă¶
Utilizatorii pot administra și utiliza un NetHSM utilizând o interfață de linie de comandă (CLI) dedicată. Nitrokey oferă nitropy, care este distribuită în baza Python pynitrokey. Cu nethsm există o aplicație terță alternativă, care este dezvoltată în crate-ul Rust nethsm-cli.