> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy a client endpoint

> Create a Generic KMIP client endpoint and download the TLS bundle that authorizes the KMIP application.

Create a client endpoint to authorize the KMIP application to use the Generic KMIP service, and protect the downloaded bundle as a credential.

<Warning>
  The endpoint ZIP contains the client private key and the password for its PKCS #12 file. Store it in a protected location, and do not send it through email or copy it into an image.
</Warning>

<Steps>
  <Step title="Open endpoint management">
    Open **Services**, select the **Deployed Services** tab, and select the Generic KMIP service that you deployed. Select **ENDPOINTS**.

    <Check>
      CryptoHub displays the **Manage Endpoints** page for the service.
    </Check>
  </Step>

  <Step title="Add the endpoint">
    Select **ADD NEW**. In the **Add Endpoint** dialog, complete these fields:

    * **Endpoint Identifier**: a name that identifies the application host, at least 4 characters. If you leave it empty, CryptoHub generates one.
    * **CryptoHub Hostname**: the CryptoHub FQDN that the application uses to reach CryptoHub. CryptoHub fills in the address that your browser used, and writes this value to `info.txt` as the KMIP address.
    * **Client Connection Type**: **ECC** for an ECC client certificate, or **RSA** for an RSA client certificate. Select the type that the application requires.

    <Check>
      The dialog shows your values in all three fields.
    </Check>
  </Step>

  <Step title="Download the endpoint">
    Select **ADD ENDPOINT** and save the downloaded ZIP in a protected administrator directory.

    <Check>
      CryptoHub displays **Endpoint created**, and the browser downloads a ZIP named after the endpoint identifier.
    </Check>
  </Step>

  <Step title="Record the KMIP address">
    Open `info.txt` and record the service name and the address. Use this address in the application's KMIP settings.

    <Check>
      `info.txt` names the service that you deployed, and its address ends with `:5696`.
    </Check>
  </Step>
</Steps>

## Endpoint ZIP contents

| File | Description |
| - | - |
| `ca-chain.pem` | CA certificate bundle. The application uses it to verify the CryptoHub KMIP server certificate. It also contains the CA that issued the client certificate. |
| `client-cert.pem` | Client TLS certificate for the endpoint. |
| `credential.txt` | Identity name that CryptoHub created for the endpoint. |
| `info.txt` | Service name, service identifier, and the KMIP address in the form `<CryptoHub Hostname>:5696`. |
| `pki.p12` | Full client PKI in encrypted PKCS #12 format: the CA chain, the client certificate, and the client private key. |
| `pki-password.txt` | Password for `pki.p12`. |
| `Client App TLS CA <number>.cer` | CA certificate that CryptoHub uses to issue client endpoint TLS certificates. The number is specific to your CryptoHub. |
| `Futurex Test Root CA (ECC).cer` and `Futurex Test Root SSL CA.cer` | Futurex test root CAs for the embedded Futurex test TLS certificates. |

The ZIP does not contain the KMIP server certificate. The application receives it during the TLS handshake. Configure `ca-chain.pem` as the application's server CA.

<Note>
  Each endpoint has its own identity and client certificate. Create a separate endpoint for each application host or cluster member that needs its own credential.
</Note>
