> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Install and configure Futurex PKCS #11

> Install the complete endpoint unit and choose the credential mode required by the application.

Extract the endpoint ZIP and install the complete unit:

```shell theme={null}
sudo install -d -m 700 /etc/futurex-pkcs11
sudo install -m 755 libcryptohub-pkcs11.so \
  /usr/local/lib/libcryptohub-pkcs11.so
sudo install -m 755 pkcs11-manager /usr/local/bin/pkcs11-manager
sudo cp -- *.crt *.pem *.p12 cryptohub.json /etc/futurex-pkcs11/
sudo chown -R root:root /etc/futurex-pkcs11
sudo chmod 600 /etc/futurex-pkcs11/*
```

Set `CHLIBS_CONFIG=/etc/futurex-pkcs11/cryptohub.json` in the real application process. Keep every referenced TLS file beside the configuration and keep TLS verification enabled.

## Config-carried mode

Use this mode only when the application suppresses `C_Login`. Keep the endpoint username and password in `cryptohub.json`. Do not configure a PIN source.

## PIN-carried mode

Use this mode when the application calls `C_Login`:

```shell theme={null}
ENDPOINT_PASSWORD="$(sudo jq -r '.authentication.users[0].password' \
  /etc/futurex-pkcs11/cryptohub.json)"
printf '%s\n' "$ENDPOINT_PASSWORD" \
  | sudo install -m 600 -o root -g root /dev/stdin \
      /etc/futurex-pkcs11/token-pin
sudo jq '
  .authentication.users |= map({username}) |
  .pkcs11.check_already_logged_in = true
' /etc/futurex-pkcs11/cryptohub.json \
  | sudo install -m 600 -o root -g root /dev/stdin \
      /etc/futurex-pkcs11/cryptohub.json.new
sudo mv /etc/futurex-pkcs11/cryptohub.json.new \
  /etc/futurex-pkcs11/cryptohub.json
unset ENDPOINT_PASSWORD
```

<Warning>
  Do not combine the modes. A config-carried password plus consumer C\_Login can produce `CKR_USER_ALREADY_LOGGED_IN`.
</Warning>

Verify the module:

```shell theme={null}
sudo env CHLIBS_CONFIG=/etc/futurex-pkcs11/cryptohub.json \
  pkcs11-tool \
  --module /usr/local/lib/libcryptohub-pkcs11.so \
  --list-token-slots
```

<Check>
  The output lists the Futurex token in slot 0.
</Check>
