Skip to main content
Use this page to check the main requirements and configuration values. Follow the full workflow for first-time deployment.

Required software

  • CryptoHub 7.3.0.x with the CryptoHub Client Library Ansible template
  • Linux control node; validated on Ubuntu 24.04
  • Ansible Core 2.12 or later; validated on 2.16.3
  • OpenSSL 3
  • Latchset pkcs11-provider 1.2.0 at commit c7a5c8b62a0ff012b16574f01651254ef7e664ee
  • OpenSC
  • OpenSSH
  • sshpass 1.06 or later

CryptoHub endpoint

  • Endpoint type: UserPass
  • Platform: Linux OpenSSL 3
  • Transport: CryptoHub REST API over TLS on port 443
  • Key policy: TRUSTED RSA with Sign and Verify usages

Control-node files

  • PKCS #11 module: /usr/local/lib/libcryptohub-pkcs11.so
  • Client configuration: /etc/ansible/cryptohub/cryptohub.json
  • Provider configuration: /etc/ansible/cryptohub/openssl-cryptohub.cnf
  • Provider PIN file: /etc/ansible/cryptohub/chlibs-pin.txt
  • SSH PIN variable source: /etc/ansible/cryptohub/ssh-pin-vars.yml

Required environment

  • Set CHLIBS_CONFIG in the shell that launches ansible-playbook for native SSH connections.
  • Set OPENSSL_CONF and CHLIBS_CONFIG in the environment of OpenSSL command tasks.
  • Set ansible_ssh_pkcs11_provider to the CryptoHub module for managed SSH hosts.

Success signals

  • Signing: Verified OK and failed=0 in the play recap.
  • SSH: the managed-host command succeeds with unreachable=0 and failed=0.
  • Negative control: omitting the protected PIN produces a PIN-specific failure instead of using another authentication method.