> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate PKCS #11 connectivity

> Use Smallstep KMS commands and independent OpenSSL verification to prove the direct no-PIN FxChlibs signing path.

Prove the direct PKCS #11 path before starting the CA. Run this page after generating the intermediate key.

## Confirm the token

Load the saved variables and list the token:

```shell title="Shell" theme={null}
source /etc/step-ca/cryptohub.env
export CHLIBS_CONFIG

pkcs11-tool \
  --module "$FUTUREX_DIR/libcryptohub-pkcs11.so" \
  --list-token-slots
```

The output includes a token whose label matches `STEP_TOKEN_LABEL`.

<Warning>
  Do not add `--login` to this check and do not add a PIN to the KMS URI. OpenSC can force a separate interactive login, while Smallstep's no-PIN KMS route intentionally skips `C_Login` and uses the credential in `cryptohub.json`.
</Warning>

## Retrieve the intermediate public key

```shell title="Shell" theme={null}
step kms key \
  --kms "$STEP_KMS_URI" \
  "$STEP_INTERMEDIATE_KEY" \
  > /tmp/smallstep-intermediate-public.pem

openssl pkey \
  -pubin \
  -in /tmp/smallstep-intermediate-public.pem \
  -noout
```

The first command writes a PEM public key, and OpenSSL parses it without an error.

## Sign and verify a test file

```shell title="Shell" theme={null}
printf 'Smallstep CryptoHub connectivity test\n' \
  > /tmp/smallstep-connectivity.txt

step kms sign \
  --alg SHA256 \
  --in /tmp/smallstep-connectivity.txt \
  --kms "$STEP_KMS_URI" \
  "$STEP_INTERMEDIATE_KEY" \
  > /tmp/smallstep-connectivity.sig.b64

base64 -d \
  /tmp/smallstep-connectivity.sig.b64 \
  > /tmp/smallstep-connectivity.sig

openssl dgst \
  -sha256 \
  -verify /tmp/smallstep-intermediate-public.pem \
  -signature /tmp/smallstep-connectivity.sig \
  /tmp/smallstep-connectivity.txt
```

The final command prints:

```text title="Expected result" theme={null}
Verified OK
```

This result proves that Smallstep loaded the endpoint module, authenticated through `cryptohub.json`, found the CryptoHub key, and completed a private-key operation without a PKCS #11 PIN.
