Skip to main content
Prepare the CryptoHub appliance, Ansible control node, identities, and network path before deploying the integration.

CryptoHub requirements

  • Use CryptoHub 7.3.0.x with the CryptoHub Client Library Ansible template. This guide was validated with build 7.3.0.0b.
  • Use administrator identities under dual control to deploy the service and endpoint. The deployment requires Custom Services: Manage and Custom Services: Deploy.
  • Create a UserPass endpoint. Both validated Ansible consumer paths use the endpoint password as their PKCS #11 PIN.

Control-node requirements

  • Use a Linux control node. This guide was validated on Ubuntu 24.04.
  • Install Ansible Core 2.12 or later. The native ansible_ssh_pkcs11_provider option was added in Ansible Core 2.12; this guide was validated on 2.16.3.
  • Install OpenSSL 3, OpenSC, OpenSSH, jq, and sshpass 1.06 or later. OpenSC supplies pkcs11-tool; sshpass supplies the PIN to Ansible’s SSH connection plugin through an input pipe.
  • Build Latchset pkcs11-provider 1.2.0 for OpenSSL signing tasks. Ubuntu 24.04’s 0.3 package does not support the signing operation in this guide.
  • Obtain root access. The client configuration, TLS material, and PIN files must be readable by the Ansible runner and protected from other users.

Network requirements

  • Allow outbound TCP port 443 from the Ansible control node to the CryptoHub REST API. The client library uses this path for authentication and key operations.
  • Allow TCP port 22 from the control node to each managed SSH host.
  • Exempt the CryptoHub FQDN from TLS inspection. TLS inspection terminates the client-authenticated connection and prevents the endpoint TLS identity from reaching CryptoHub.
Keep TLS verification enabled and trust the CryptoHub certificate through the CA files in the endpoint download.