Prove the direct PKCS #11 path before starting the CA. Run this page after generating the intermediate key.
Confirm the token
Load the saved variables and list the token:
The output includes a token whose label matches STEP_TOKEN_LABEL.
Do not add --login to this check and do not add a PIN to the KMS URI. OpenSC can force a separate interactive login, while Smallstep’s no-PIN KMS route intentionally skips C_Login and uses the credential in cryptohub.json.
The first command writes a PEM public key, and OpenSSL parses it without an error.
Sign and verify a test file
The final command prints:
This result proves that Smallstep loaded the endpoint module, authenticated through cryptohub.json, found the CryptoHub key, and completed a private-key operation without a PKCS #11 PIN.