cryptohub.json in the environment, matching the wiring from the previous section:
Confirm the CryptoHub token label
The token label yourpkcs11: URIs reference is the cryptohubs[].label value defined in your cryptohub.json. Confirm it before building URIs:
pkcs11-manager. Pass the configuration path as its first argument, then use its initialization, login, and slot-listing menu actions:
pkcs11-tool is installed (from the opensc package), list the token slots directly against the CryptoHub module:
Create a key pair in CryptoHub
If you do not yet have a key in CryptoHub, use the key-generation action in the interactivepkcs11-manager menu. Give the key a label you will reference from OpenSSL, for example my_rsa2048_key.
config.json, which is what the OpenSSL examples below exercise. If your use case needs both Encrypt/Decrypt and Sign/Verify usages on the same key, first complete Enable the EDSV multi-usage combination for asymmetric keys.
After generation, confirm the key is reachable by URI through the provider:
<label> with the token label confirmed above and my_rsa2048_key with your key’s label.
Note: Keep provider URIs free of pin-value. The dedicated OpenSSL provider configuration supplies the module PIN from the protected pin file. With a 1.x provider, pin-source is an alternative to the configuration directive, not an additional PIN source.
OpenSSL example commands
The following commands use the key created in CryptoHub above. In each command that uses a CryptoHub key, the pkcs11 provider is specified with-provider pkcs11 -provider default, and the key is referenced by a pkcs11: URI.
This section does not provide an exhaustive list of OpenSSL commands that you can run through the pkcs11 provider. It gives a few examples of use cases and confirms everything was configured correctly. Refer to the OpenSSL documentation (www.openssl.org/docs/) for the full list of compatible commands. Running one of these commands successfully forces a cryptographic operation against the key in CryptoHub: this is the proof that the provider reached CryptoHub, not merely that the configuration parses.
Example 1: Output the public key
If the command succeeds, the
my_rsa2048_pubkey.pem file is generated and contains the public key.Example 2: Encrypt and decrypt data
1
Generate a file,
clear_data, containing sample ASCII data:2
Encrypt the
clear_data file using the CryptoHub-backed public key and output the results to encrypted_data:3
Decrypt the
encrypted_data file using the CryptoHub-backed private key and output the results to decrypted_data:4
Confirm that
clear_data and decrypted_data are identical:If the command runs successfully and the files are identical, no output is displayed.
Example 3: Sign a file and verify the signature
1
Sign the
clear_data file using the CryptoHub-backed private key and output the signature to clear_data.sig:2
Verify the signature using the CryptoHub-backed public key:
If the signature was verified successfully, the message
Verified OK displays on the screen.Example 4: Create a self-signed Root CA
1
Generate a self-signed CA certificate using the CryptoHub-backed private key:
2
When prompted, enter information about the self-signed CA certificate.
A successful command execution generates the
ssl-ca-cert.pem file.Example 5: Generate a CSR
1
Generate a CSR using the CryptoHub-backed private key:
2
When prompted, enter information about the certificate.
A successful command execution generates the
ssl-client-cert-req.csr file.Example 6: Sign a CSR
A successful command execution generates the
signed-client-cert.pem file, containing the signed certificate. A serial number file, ssl-ca-cert.srl, is also created to track the certificate’s serial number for future CA operations.
