Install the CryptoHub Client Library (FXCHLIBS)
Your OpenSSL-based application is a Linux OpenSSL-engine consumer, so it reaches CryptoHub through the Linux PKCS #11 module (libcryptohub-pkcs11.so) loaded through the OpenSSL pkcs11 engine. The endpoint download contains the module, its supporting tool, configuration, credentials, and TLS files.
-
Extract the endpoint zip on the OpenSSL host. It provides:
libcryptohub-pkcs11.so: The CryptoHub PKCS #11 module loaded by the OpenSSL engine.pkcs11-manager: The interactive utility for initializing the module and checking slots and objects.cryptohub.json: The service-matched configuration with the endpoint’s UserPass credential.- TLS material: The CA chain and client PKCS #12 material referenced by
cryptohub.json.
-
Install the module and utility in locations available to the account that runs OpenSSL. For example:
Configure the connection (cryptohub.json)
The CryptoHub Client Library reads its connection and authentication settings from a cryptohub.json file. The endpoint download you generated above provides a pre-filled cryptohub.json and TLS material for your instance: use it. It carries the CryptoHub host and REST API port, the service reference, the endpoint’s authentication material, and the TLS settings, on top of the library-behavior defaults pinned by this template.
-
Place
cryptohub.jsonand every TLS file from the same endpoint download in one protected directory that the OpenSSL account can read. Preserve the filenames because the configuration uses paths relative to its own directory. -
Verify
cryptohubs[].base_uri. If the host is empty, such ashttps://:443, enter the CryptoHub FQDN or address. Endpoint downloads do not always populate it. -
Confirm that every file referenced by
cryptohubs[].tls.authoritiesandcryptohubs[].tls.client_fileis present. If one is missing, generate a new endpoint download; do not remove the client-certificate setting. Keep TLS verification enabled and trust CryptoHub through the shipped CA files. -
Set
global.key_protectiontoPROTECTED. The test procedure uses one RSA key for signing and decryption, andTRUSTEDdoes not support that mixed usage set. -
Point the library at the file by setting the
CHLIBS_CONFIGenvironment variable to its full path. The variable must be present in the environment of every process that loads the module:On POSIX systems the module also searches./cryptohub.json,../config/cryptohub.json, and/etc/cryptohub.jsonwhenCHLIBS_CONFIGis unset, but settingCHLIBS_CONFIGexplicitly is the most reliable option for a service account.
cryptohub.json and trust CryptoHub’s certificate through its CA.
Note: The service and its key store must exist in CryptoHub before the service reference in cryptohub.json can resolve. You deployed this service earlier in this guide, so it already exists.
Verify the module
Use the bundledpkcs11-manager to confirm the module can reach and authenticate to CryptoHub before configuring the OpenSSL engine. It is an interactive menu utility, not an automatic connectivity probe, and its first argument is the configuration path. Complete the initialization, login, and slot-listing menu actions.

