Skip to main content
Complete these prerequisites before you deploy the integration.

Software and platform

  • Use CryptoHub 7.3.0.x build 7.3.0.0b or later. This guide uses the REST-based CryptoHub Client Library rather than the legacy Host API library.
  • Use Ubuntu 24.04 with strongSwan 5.9.13 or a compatible release. Package names and AppArmor paths differ on other distributions.
  • Install strongswan, strongswan-swanctl, strongswan-pki, and libstrongswan-extra-plugins. The extra-plugins package provides libstrongswan-pkcs11.so.
  • Install opensc for pkcs11-tool verification.
Run:
Run ipsec --version, swanctl --version, and test -f /usr/lib/ipsec/plugins/libstrongswan-pkcs11.so. Each command must succeed.

Network access

  • Allow the strongSwan gateway to reach CryptoHub over TCP 443. FxChlibs sends authentication and signing requests over this connection.
  • Allow IKEv2 between the gateways over UDP 500 and UDP 4500. Permit ESP when the peers do not use UDP encapsulation.
  • Exempt the CryptoHub TLS connection from interception. The endpoint bundle pins the trust material that authenticates CryptoHub.
Verify CryptoHub reachability:
Replace <CRYPTOHUB_HOST> with the CryptoHub hostname. The command must return a status document.

CryptoHub access

Obtain two CryptoHub administrator identities. Dual control protects service and endpoint deployment.

Version and scope

This guide was validated on Ubuntu 24.04 with strongSwan 5.9.13. It does not provide RHEL package names or SELinux policy.