Required software
- CryptoHub 7.3.0.x with the CryptoHub Client Library Ansible template
- Linux control node; validated on Ubuntu 24.04
- Ansible Core 2.12 or later; validated on 2.16.3
- OpenSSL 3
- Latchset
pkcs11-provider1.2.0 at commitc7a5c8b62a0ff012b16574f01651254ef7e664ee - OpenSC
- OpenSSH
sshpass1.06 or later
CryptoHub endpoint
- Endpoint type: UserPass
- Platform: Linux OpenSSL 3
- Transport: CryptoHub REST API over TLS on port 443
- Key policy: TRUSTED RSA with Sign and Verify usages
Control-node files
- PKCS #11 module:
/usr/local/lib/libcryptohub-pkcs11.so - Client configuration:
/etc/ansible/cryptohub/cryptohub.json - Provider configuration:
/etc/ansible/cryptohub/openssl-cryptohub.cnf - Provider PIN file:
/etc/ansible/cryptohub/chlibs-pin.txt - SSH PIN variable source:
/etc/ansible/cryptohub/ssh-pin-vars.yml
Required environment
- Set
CHLIBS_CONFIGin the shell that launchesansible-playbookfor native SSH connections. - Set
OPENSSL_CONFandCHLIBS_CONFIGin the environment of OpenSSL command tasks. - Set
ansible_ssh_pkcs11_providerto the CryptoHub module for managed SSH hosts.
Success signals
- Signing:
Verified OKandfailed=0in the play recap. - SSH: the managed-host command succeeds with
unreachable=0andfailed=0. - Negative control: omitting the protected PIN produces a PIN-specific failure instead of using another authentication method.

