unsupported kms type 'pkcs11': step-ca is compiled without cgo or PKCS11 support
Cause: The standard step-ca package or release binary is running. It cannot load a native PKCS #11 module.
Fix: Stop that process and run the pinned HSM image:
Shell
Smallstep CA/0.30.2. Then repeat Start step-ca.
Please enter User PIN from pkcs11-tool
Cause: OpenSC initiated C_Login before a private-key operation. The Smallstep direct-loader route does not use that login model.
Fix: Do not add --login, pin-value, or pin-source. Use step kms sign for the Smallstep signing check and keep the endpoint UserPass credential in protected cryptohub.json.
Shell
error initializing PKCS#11: could not open PKCS#11
Cause: Smallstep cannot load the module or its endpoint configuration. A missing CHLIBS_CONFIG produces this error before key access.
Fix: Verify the environment, module, configuration, and referenced TLS files:
Shell
/opt/futurex is mounted at the same path inside the container.
Log file ... is not writable; using temporary log file
Cause: A host process created the log without group-write permission before the container started.
Fix: Restore the runtime group and file mode, then restart the container:
Shell
C_SignInit and C_SignFinal entries.
x509: provided PrivateKey doesn't match parent's PublicKey
Cause: ca.json references one CryptoHub key while intermediate_ca.crt contains a different public key. This often occurs when the software intermediate from step ca init remains in place.
Fix: Reissue the intermediate certificate with the exact STEP_INTERMEDIATE_KEY, then compare both public keys before replacing the certificate. Follow Configure step-ca to use CryptoHub.
Do not delete or replace the CryptoHub key until the public-key comparison and root-chain verification pass.
The container reports a missing path under /home/step/.step
Cause: ca.json still contains host paths such as /var/lib/smallstep/.step/db. Those paths do not exist in the container.
Fix: Set root, crt, and db.dataSource to their /home/step/.step/ paths, then restart:
Shell
{"status":"ok"} after the restart.
