cryptohub.json in the environment, matching the wiring from the previous section:
CHLIBS_CONFIG must be present in the environment of any process that loads the module. The engine uses the module set through MODULE_PATH in openssl.cnf, so you do not set a separate module environment variable.
Confirm the CryptoHub token label
The token label yourpkcs11: URIs reference is the cryptohubs[].label value defined in your cryptohub.json (the default is CryptoHub). If OpenSC’s pkcs11-tool is installed, list the token slots directly against the CryptoHub module to confirm it:
Create a key pair in CryptoHub
If you do not yet have a key in CryptoHub, generate one with the bundled interactivepkcs11-manager. Pass the configuration path as its first argument, initialize the module, log in with the endpoint’s UserPass password, and select the key-generation action. Give the key a label you will reference from OpenSSL, for example my_rsa2048_key.
config.json (Sign, Verify, Encrypt, and Decrypt), which is what the OpenSSL examples below exercise.
Keep the ENGINE configuration and
pkcs11: URIs free of PIN, pin-value, and pin-source. The CryptoHub Client Library authenticates with the credential in the endpoint configuration.OpenSSL example commands
Below are several OpenSSL example commands, most of which use the key created in CryptoHub above. In the commands that use a CryptoHub key, the pkcs11 OpenSSL engine is specified.The purpose of this section is not to provide an exhaustive list of OpenSSL commands that you can run using the pkcs11 OpenSSL Engine, but rather to give a few examples of use-cases and confirm that everything is configured correctly. Refer to OpenSSL’s documentation for the full list of compatible commands.
Example 1: Output the public key from the CryptoHub
Perform the following step to output the public key from the CryptoHub:1
In a terminal, run the following command to output the public key:
If the command succeeds, it should output the public key to the screen, similar to the following example:
Example 2: Encrypt and decrypt data
Perform the following steps to encrypt data with the public key and decrypt it with the CryptoHub-stored private key:1
In a terminal, run the following command to generate a file called
clear_data containing sample ASCII data:2
Retrieve the public key from the CryptoHub.
3
Encrypt the
clear_data file by using the public key retrieved from CryptoHub and output the results to a file called encrypted_data.4
Decrypt the
encrypted_data file by using the CryptoHub-stored private key and output the results to a file called clear_data2.5
Confirm that the contents of the
clear_data and clear_data2 files are identical.If the command runs successfully and the files are identical, no output is displayed.
Example 3: Sign a data file
Perform the following steps to sign a data file using the CryptoHub-stored private key and verify the signature using the public key:1
Sign the
clear_data file by using the CryptoHub-stored private key and output the signature to a file called clear_data.sig.2
Verify the signature using the public key.
The command outputs
Verified OK.Example 4: Generate a CSR
Run the following command to generate a Certificate Signing Request (CSR) with the CryptoHub-stored private key:The command creates
ssl-client-cert-req.pem. Run openssl req -in ssl-client-cert-req.pem -noout -verify and confirm that it outputs Certificate request self-signature verify OK.
