Skip to main content
Start the online CA from the pinned HSM image. Bind-mount the CA state and endpoint files instead of copying either credential set into the image.

Load the runtime variables

Shell
The final command exits with status 0 when the endpoint-file group exists.

Start the container

Shell
Docker prints the new container ID. The command keeps the endpoint directory read-only, exposes the CA on port 9000, and grants the container only the supplementary group needed to read the endpoint files and append to the FxChlibs log.
The command does not pass a PKCS #11 PIN or endpoint password. FxChlibs reads the protected UserPass credential from the bind-mounted cryptohub.json.

Verify startup

Check the container state and CA health:
Shell
The health response is:
Expected result
Inspect the startup log:
Shell
The log includes these messages:
Expected result
Confirm that FxChlibs reached the intermediate key:
Shell
The output includes successful sign initialization and finalization calls. Continue to Validate the integration to issue a leaf certificate.