Install the CryptoHub Client Library (FXCHLIBS)
Your OpenSSL-based application is a Linux OpenSSL-provider consumer, so it reaches CryptoHub through the Linux PKCS #11 module (libcryptohub-pkcs11.so). This module ships inside the endpoint download you generated above: you do not need to obtain or install a separate package.
- Extract the endpoint zip on the host running your OpenSSL-based application. It provides the following files:
libcryptohub-pkcs11.so-> The CryptoHub PKCS #11 module. This is the module path the OpenSSL pkcs11 provider is pointed at. Move it to a location your application’s loader can reach: a common choice is/usr/local/lib/libcryptohub-pkcs11.so.pkcs11-manager-> Interactive menu-driven utility for initializing the module, logging in, listing slots and objects, and generating test keys.cryptohub.json-> Your deployment configuration for this endpoint, pre-filled with the connection, authentication, and TLS settings.- TLS material -> The CA files, CA chain, and any endpoint certificate material used to authenticate CryptoHub.
Configure the connection (cryptohub.json)
The CryptoHub Client Library reads its connection and authentication settings from a cryptohub.json file. The endpoint download you generated above provides a pre-filled cryptohub.json and TLS material for your instance: use it. It carries the CryptoHub host and REST API port, the service reference, the endpoint’s authentication material, and the TLS settings, on top of the library-behavior defaults pinned by this template.
The OpenSSL Provider template supports UserPass authentication only. Keep the downloaded username and password secure; the provider configuration uses the same password as its PKCS #11 PIN.
-
Place the deployed
cryptohub.json(and its TLS material) in a location the application’s service account can read, for example/etc/cryptohub.json. -
Verify
cryptohubs[].base_uri. If the host is empty, such ashttps://:443, enter the CryptoHub FQDN or address. Endpoint downloads do not always populate it. -
If
cryptohubs[].tls.client_filereferences a file that is absent from the endpoint download, such asclient.p12, remove that field. Keep TLS verification enabled and trust CryptoHub through the shipped CA files. -
Point the library at the file by setting the
CHLIBS_CONFIGenvironment variable to its full path. The variable must be present in the environment of the process that loads the module (both the shell used for the verification steps below and, later, the service that hosts your application):On POSIX systems the module also searches./cryptohub.json,../config/cryptohub.json, and/etc/cryptohub.jsonwhenCHLIBS_CONFIGis unset, but settingCHLIBS_CONFIGexplicitly is the most reliable option for a service account.
cryptohub.json and trust CryptoHub’s certificate through its CA. Accepting the server certificate without verification is only appropriate for a self-signed lab appliance that your client does not yet trust.
Note: The service and its key store must exist in CryptoHub before the service reference in cryptohub.json can resolve. You deployed this service earlier in this guide, so it already exists.
Verify the module
Use the bundledpkcs11-manager to confirm the module can reach and authenticate to CryptoHub before configuring the OpenSSL provider. It is an interactive menu utility, not an automatic connectivity probe. Its first argument is the configuration path.

