- libp11: Provides a higher-level interface (compared to the PKCS #11 library) for accessing PKCS #11 objects. It integrates with applications that use OpenSSL.
- OpenSC: Provides a set of libraries and utilities to work with smart cards. It focuses on cards that support cryptographic operations and facilitates their use in security applications such as authentication, mail encryption, and digital signatures.
- pkcs11 engine plugin: Engine plugin for the OpenSSL library that allows accessing PKCS #11 modules in a semi-transparent way.
The OpenSSL ENGINE interface is legacy and was deprecated in OpenSSL 3.x. On OpenSSL 3.x, Futurex recommends the OpenSSL provider path (see the OpenSSL Provider integration) instead. Use this ENGINE path for OpenSSL 1.1.x or where an existing application still relies on the engine interface.
- Install libp11 and OpenSC.
- Edit the OpenSSL configuration file.
Install libp11 and OpenSC
The following steps build the validated libp11 release on Ubuntu 24.04 or Debian 12.1
Install the build dependencies and OpenSC:
2
Clone libp11 0.4.21 and verify the source revision:
The revision is
ad19678991c5882d252b06ed02c4d4fb990913d0.3
Build and install libp11:
Edit the OpenSSL configuration file
Create a dedicated OpenSSL configuration for the ENGINE consumer. Do not activate the engine in the system-wide OpenSSL configuration.1
Display the OpenSSL engine directory:
The command prints an
ENGINESDIR path. Confirm that pkcs11.so exists in that directory.2
Create a dedicated OpenSSL configuration file and add the following configuration. Replace Do not add a
<openssl-engines-directory> with the ENGINESDIR value from the previous step:PIN control or a pin-value or pin-source URI attribute. The CryptoHub Client Library authenticates with the endpoint credential in cryptohub.json.3
Verify the engine configuration:
The
pkcs11 engine reports [ available ].Point the library at your cryptohub.json
Point the CryptoHub Client Library at your deployed cryptohub.json by setting CHLIBS_CONFIG in the environment of the shell (and any application) that loads the module:
CHLIBS_CONFIG must be present in the environment of any process that loads the module. The engine uses the module set through MODULE_PATH in openssl.cnf, so you do not set a separate module environment variable.
