Skip to main content
This section walks through creating a key pair in CryptoHub and running several OpenSSL commands that use it through the OpenSSL pkcs11 engine you configured in the previous section. Run these commands with cryptohub.json in the environment, matching the wiring from the previous section:
CHLIBS_CONFIG must be present in the environment of any process that loads the module. The engine uses the module set through MODULE_PATH in openssl.cnf, so you do not set a separate module environment variable.

Confirm the CryptoHub token label

The token label your pkcs11: URIs reference is the cryptohubs[].label value defined in your cryptohub.json (the default is CryptoHub). If OpenSC’s pkcs11-tool is installed, list the token slots directly against the CryptoHub module to confirm it:

Create a key pair in CryptoHub

If you do not yet have a key in CryptoHub, generate one with the bundled interactive pkcs11-manager. Pass the configuration path as its first argument, initialize the module, log in with the endpoint’s UserPass password, and select the key-generation action. Give the key a label you will reference from OpenSSL, for example my_rsa2048_key.
The key is created in CryptoHub with the asymmetric usages pinned by this template’s config.json (Sign, Verify, Encrypt, and Decrypt), which is what the OpenSSL examples below exercise.
Keep the ENGINE configuration and pkcs11: URIs free of PIN, pin-value, and pin-source. The CryptoHub Client Library authenticates with the credential in the endpoint configuration.

OpenSSL example commands

Below are several OpenSSL example commands, most of which use the key created in CryptoHub above. In the commands that use a CryptoHub key, the pkcs11 OpenSSL engine is specified.
The purpose of this section is not to provide an exhaustive list of OpenSSL commands that you can run using the pkcs11 OpenSSL Engine, but rather to give a few examples of use-cases and confirm that everything is configured correctly. Refer to OpenSSL’s documentation for the full list of compatible commands.
Running one of these commands successfully forces a cryptographic operation against the key in CryptoHub: this is the proof that the engine reached CryptoHub, not merely that the configuration parses.

Example 1: Output the public key from the CryptoHub

Perform the following step to output the public key from the CryptoHub:
1
In a terminal, run the following command to output the public key:
If the command succeeds, it should output the public key to the screen, similar to the following example:

Example 2: Encrypt and decrypt data

Perform the following steps to encrypt data with the public key and decrypt it with the CryptoHub-stored private key:
1
In a terminal, run the following command to generate a file called clear_data containing sample ASCII data:
2
Retrieve the public key from the CryptoHub.
3
Encrypt the clear_data file by using the public key retrieved from CryptoHub and output the results to a file called encrypted_data.
4
Decrypt the encrypted_data file by using the CryptoHub-stored private key and output the results to a file called clear_data2.
5
Confirm that the contents of the clear_data and clear_data2 files are identical.
If the command runs successfully and the files are identical, no output is displayed.

Example 3: Sign a data file

Perform the following steps to sign a data file using the CryptoHub-stored private key and verify the signature using the public key:
1
Sign the clear_data file by using the CryptoHub-stored private key and output the signature to a file called clear_data.sig.
2
Verify the signature using the public key.
The command outputs Verified OK.

Example 4: Generate a CSR

Run the following command to generate a Certificate Signing Request (CSR) with the CryptoHub-stored private key:
The command creates ssl-client-cert-req.pem. Run openssl req -in ssl-client-cert-req.pem -noout -verify and confirm that it outputs Certificate request self-signature verify OK.