Install the endpoint files
Extract the endpoint ZIP and change to the extracted directory. Then run:Shell
Shell
Inspect the endpoint configuration
Run structural checks without printing credentials:Shell
Do not add
pin-value, pin-source, or another PKCS #11 PIN. Smallstep skips C_Login when the URI contains no PIN, and FxChlibs authenticates from the protected UserPass entry in cryptohub.json.Configure the runtime paths
Create a protected environment file for the non-secret module and key references. Choose a hexadecimal key ID and a descriptive key label when prompted.Shell
Shell
module-path and token, and that the key URI contains both id and object. Neither URI contains a PIN parameter.
Prepare the log path
Create a group-writable log path for the container without relaxing the endpoint-file permissions:Shell
step-ca group when it starts, so it can append to this log while the endpoint credential remains protected.
Validate the installed runtime
Shell

