This article is valid for Certificate Manager 8.5 and later.
To initialize a Hardware Security Module (HSM) with key pairs and certificates or a secret key, the command-line program hwsetup is provided with Nexus Certificate Manager (CM).
The program is located in the <install_root>/tools directory where CM is installed.
When creating key pairs or importing certificates, the PKCS #11 library of the HSM device must allow certificate objects to be stored in the same token as the key pairs.
To print information about the cryptoki interface:
hwsetup -libname <pkcs11lib> -info