Skip to main content
Once you deploy the service in CryptoHub, set up a client endpoint. An endpoint is a device authorized to access the service. Use the Endpoints menu to view and manage these devices. You can also add new endpoints by selecting [ Add New ]. Unlike the legacy Host-API libraries (FXPKCS11 and FXCNG), the CryptoHub Client Library reaches CryptoHub over the v2 REST API on port 443. The CryptoHub Client Library ships inside the endpoint download: deploying an endpoint provisions the identity, connection details, and TLS material that the library uses to authenticate, along with the library module and its supporting tools.
1
Go to the Endpoints menu for the service you deployed.
2
In the Manage Endpoints menu, select [ Add New ].
3
In the Add Endpoint dialog:
  • Enter identifier or leave empty for auto-generation.
  • Leave the auto-populated CryptoHub Hostname as is.
  • Select the Platform for the Endpoint.
4
Select [ Add Endpoint ]. The browser prompts you to download a zip file containing the CryptoHub Client Library PKCS #11 module, TLS certificates, and a cryptohub.json file preconfigured to connect to your CryptoHub instance. Keep this download secure: it is a credential.
To change the endpoint’s UserPass password, go to Identity and Access > Applications & Partitions. Find the application, then select Authentication in its Manage section. Update the protected PIN file on the OpenSSL host to contain the same password.