- Use CryptoHub 7.3.0.x build 7.3.0.0b or later. This route uses the REST-based CryptoHub Client Library, not Host API port 2001.
- Use a supported Linux host with root access. The baseline was validated on Ubuntu 24.04.5.
- Allow the host to reach CryptoHub over TCP 443. Exempt this TLS connection from interception so the endpoint trust material authenticates CryptoHub.
- Install OpenSC and OpenSSL for the generic PIN-carried smoke test.
Generic Futurex PKCS #11
Before you start
Prepare CryptoHub 7.3.0.x, Linux, network access, and endpoint permissions for the PKCS #11 baseline.
Prepare the following environment:
Deploy the service under dual control with two CryptoHub administrator identities.

