> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy the client endpoint

> Create a Linux UserPass endpoint and download the complete FxChlibs configuration and TLS bundle for the step-ca host.

Create one endpoint for each step-ca host. The downloaded ZIP contains the module, configuration, credential, and TLS files that bind the host to the deployed service.

<Warning>
  Treat the endpoint ZIP as a credential. Store it outside source control and remove unprotected copies after installing the endpoint.
</Warning>

<Steps>
  <Step>
    Open the deployed Smallstep service and select **Endpoints**.
  </Step>

  <Step>
    Select **\[ Add endpoint ]**, then select the **step-ca** endpoint type.
  </Step>

  <Step>
    Enter an **Endpoint Name** that identifies the CA host.

    Keep **Authentication Type** set to **UserPass**.
  </Step>

  <Step>
    Select **Linux OpenSSL 3.x** as the platform.

    This platform supplies the Linux FxChlibs module used by the validated x86-64 container route.
  </Step>

  <Step>
    Set **Device Address** to the CryptoHub FQDN that the CA host uses, then create the endpoint.
  </Step>

  <Step>
    Download the endpoint ZIP and move it to the step-ca host through an approved secure transfer method.
  </Step>
</Steps>

Confirm that the ZIP contains at least these files:

| File | Purpose |
| - | - |
| `libcryptohub-pkcs11.so` | FxChlibs PKCS #11 module loaded by Smallstep |
| `pkcs11-manager` | Module and token diagnostic utility |
| `cryptohub.json` | Service, authentication, TLS, token-label, and usage configuration |
| `client.p12` and `client-cert.pem` | Endpoint TLS identity material |
| `ca-chain.pem` and CA certificate files | Trust for the CryptoHub REST connection |

<Check>
  The generated `cryptohub.json` names the deployed service and enables TLS verification. Do not replace it with a sample configuration from another service.
</Check>
