Skip to main content
Install the CryptoHub Client Library (FXCHLIBS)
Your OpenSSL-based application is a Linux OpenSSL-provider consumer, so it reaches CryptoHub through the Linux PKCS #11 module (libcryptohub-pkcs11.so). This module ships inside the endpoint download you generated above: you do not need to obtain or install a separate package.
  1. Extract the endpoint zip on the host running your OpenSSL-based application. It provides the following files:
    • libcryptohub-pkcs11.so -> The CryptoHub PKCS #11 module. This is the module path the OpenSSL pkcs11 provider is pointed at. Move it to a location your application’s loader can reach: a common choice is /usr/local/lib/libcryptohub-pkcs11.so.
    • pkcs11-manager -> Interactive menu-driven utility for initializing the module, logging in, listing slots and objects, and generating test keys.
    • cryptohub.json -> Your deployment configuration for this endpoint, pre-filled with the connection, authentication, and TLS settings.
    • TLS material -> The CA files, CA chain, and any endpoint certificate material used to authenticate CryptoHub.
Configure the connection (cryptohub.json)
The CryptoHub Client Library reads its connection and authentication settings from a cryptohub.json file. The endpoint download you generated above provides a pre-filled cryptohub.json and TLS material for your instance: use it. It carries the CryptoHub host and REST API port, the service reference, the endpoint’s authentication material, and the TLS settings, on top of the library-behavior defaults pinned by this template. The OpenSSL Provider template supports UserPass authentication only. Keep the downloaded username and password secure; the provider configuration uses the same password as its PKCS #11 PIN.
  1. Place the deployed cryptohub.json (and its TLS material) in a location the application’s service account can read, for example /etc/cryptohub.json.
  2. Verify cryptohubs[].base_uri. If the host is empty, such as https://:443, enter the CryptoHub FQDN or address. Endpoint downloads do not always populate it.
  3. If cryptohubs[].tls.client_file references a file that is absent from the endpoint download, such as client.p12, remove that field. Keep TLS verification enabled and trust CryptoHub through the shipped CA files.
  4. Point the library at the file by setting the CHLIBS_CONFIG environment variable to its full path. The variable must be present in the environment of the process that loads the module (both the shell used for the verification steps below and, later, the service that hosts your application):
    On POSIX systems the module also searches ./cryptohub.json, ../config/cryptohub.json, and /etc/cryptohub.json when CHLIBS_CONFIG is unset, but setting CHLIBS_CONFIG explicitly is the most reliable option for a service account.
Note: For production deployments, keep TLS verification enabled in cryptohub.json and trust CryptoHub’s certificate through its CA. Accepting the server certificate without verification is only appropriate for a self-signed lab appliance that your client does not yet trust. Note: The service and its key store must exist in CryptoHub before the service reference in cryptohub.json can resolve. You deployed this service earlier in this guide, so it already exists.
Verify the module
Use the bundled pkcs11-manager to confirm the module can reach and authenticate to CryptoHub before configuring the OpenSSL provider. It is an interactive menu utility, not an automatic connectivity probe. Its first argument is the configuration path.
Complete the initialization, login, and slot-listing menu actions. A successful login and slot listing confirm the module reaches CryptoHub and accepts the endpoint credential.