Skip to main content
Install the complete endpoint bundle in one protected directory. Both the host bootstrap tools and the step-ca container use this directory.
The endpoint configuration contains a UserPass credential and TLS private-key material. Do not print cryptohub.json, copy it into an image, or make the directory world-readable.

Install the endpoint files

Extract the endpoint ZIP and change to the extracted directory. Then run:
Shell
Confirm the module loads all shared libraries:
Shell
No output means every shared-library dependency resolved.

Inspect the endpoint configuration

Run structural checks without printing credentials:
Shell
The command exits with status 0 when the endpoint targets a TRUSTED Sign/Verify key and contains complete UserPass and TLS settings.
Do not add pin-value, pin-source, or another PKCS #11 PIN. Smallstep skips C_Login when the URI contains no PIN, and FxChlibs authenticates from the protected UserPass entry in cryptohub.json.

Configure the runtime paths

Create a protected environment file for the non-secret module and key references. Choose a hexadecimal key ID and a descriptive key label when prompted.
Shell
Load the variables into the current shell:
Shell
Confirm that the KMS URI contains module-path and token, and that the key URI contains both id and object. Neither URI contains a PIN parameter.

Prepare the log path

Create a group-writable log path for the container without relaxing the endpoint-file permissions:
Shell
The step-ca container joins the numeric step-ca group when it starts, so it can append to this log while the endpoint credential remains protected.

Validate the installed runtime

Shell
All four checks exit with status 0. Continue to Install Smallstep and the HSM image.