CryptoHub requirements
- Use CryptoHub 7.3.0.x with the CryptoHub Client Library Ansible template. This guide was validated with build 7.3.0.0b.
- Use administrator identities under dual control to deploy the service and endpoint. The deployment requires Custom Services: Manage and Custom Services: Deploy.
- Create a UserPass endpoint. Both validated Ansible consumer paths use the endpoint password as their PKCS #11 PIN.
Control-node requirements
- Use a Linux control node. This guide was validated on Ubuntu 24.04.
- Install Ansible Core 2.12 or later. The native
ansible_ssh_pkcs11_provideroption was added in Ansible Core 2.12; this guide was validated on 2.16.3. - Install OpenSSL 3, OpenSC, OpenSSH,
jq, andsshpass1.06 or later. OpenSC suppliespkcs11-tool;sshpasssupplies the PIN to Ansible’s SSH connection plugin through an input pipe. - Build Latchset
pkcs11-provider1.2.0 for OpenSSL signing tasks. Ubuntu 24.04’s 0.3 package does not support the signing operation in this guide. - Obtain root access. The client configuration, TLS material, and PIN files must be readable by the Ansible runner and protected from other users.
Network requirements
- Allow outbound TCP port 443 from the Ansible control node to the CryptoHub REST API. The client library uses this path for authentication and key operations.
- Allow TCP port 22 from the control node to each managed SSH host.
- Exempt the CryptoHub FQDN from TLS inspection. TLS inspection terminates the client-authenticated connection and prevents the endpoint TLS identity from reaching CryptoHub.

