> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Before you start

> Review the CryptoHub, Ansible, Linux, identity, and network requirements for the PKCS #11 integration.

Prepare the CryptoHub appliance, Ansible control node, identities, and network
path before deploying the integration.

## CryptoHub requirements

* Use CryptoHub 7.3.0.x with the CryptoHub Client Library **Ansible** template.
  This guide was validated with build 7.3.0.0b.
* Use administrator identities under dual control to deploy the service and
  endpoint. The deployment requires **Custom Services: Manage** and
  **Custom Services: Deploy**.
* Create a UserPass endpoint. Both validated Ansible consumer paths use the
  endpoint password as their PKCS #11 PIN.

## Control-node requirements

* Use a Linux control node. This guide was validated on Ubuntu 24.04.
* Install Ansible Core 2.12 or later. The native
  `ansible_ssh_pkcs11_provider` option was added in Ansible Core 2.12; this
  guide was validated on 2.16.3.
* Install OpenSSL 3, OpenSC, OpenSSH, `jq`, and `sshpass` 1.06 or later.
  OpenSC supplies `pkcs11-tool`; `sshpass` supplies the PIN to Ansible's SSH
  connection plugin through an input pipe.
* Build Latchset `pkcs11-provider` 1.2.0 for OpenSSL signing tasks. Ubuntu
  24.04's 0.3 package does not support the signing operation in this guide.
* Obtain root access. The client configuration, TLS material, and PIN files
  must be readable by the Ansible runner and protected from other users.

## Network requirements

* Allow outbound TCP port 443 from the Ansible control node to the CryptoHub
  REST API. The client library uses this path for authentication and key
  operations.
* Allow TCP port 22 from the control node to each managed SSH host.
* Exempt the CryptoHub FQDN from TLS inspection. TLS inspection terminates the
  client-authenticated connection and prevents the endpoint TLS identity from
  reaching CryptoHub.

Keep TLS verification enabled and trust the CryptoHub certificate through the
CA files in the endpoint download.
