Software and platform
- Use CryptoHub 7.3.0.x build 7.3.0.0b or later. This guide uses the REST-based CryptoHub Client Library rather than the legacy Host API library.
- Use Ubuntu 24.04 with strongSwan 5.9.13 or a compatible release. Package names and AppArmor paths differ on other distributions.
- Install
strongswan,strongswan-swanctl,strongswan-pki, andlibstrongswan-extra-plugins. The extra-plugins package provideslibstrongswan-pkcs11.so. - Install
openscforpkcs11-toolverification.
Run
ipsec --version, swanctl --version, and test -f /usr/lib/ipsec/plugins/libstrongswan-pkcs11.so. Each command must succeed.Network access
- Allow the strongSwan gateway to reach CryptoHub over TCP 443. FxChlibs sends authentication and signing requests over this connection.
- Allow IKEv2 between the gateways over UDP 500 and UDP 4500. Permit ESP when the peers do not use UDP encapsulation.
- Exempt the CryptoHub TLS connection from interception. The endpoint bundle pins the trust material that authenticates CryptoHub.
<CRYPTOHUB_HOST> with the CryptoHub hostname. The command must return a status document.
CryptoHub access
Obtain two CryptoHub administrator identities. Dual control protects service and endpoint deployment.Version and scope
This guide was validated on Ubuntu 24.04 with strongSwan 5.9.13. It does not provide RHEL package names or SELinux policy.

