> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure strongSwan to load the Futurex PKCS #11 module

> Register the CryptoHub Client Library with charon and enable operation logging.

Register the endpoint module in strongSwan's native PKCS #11 plugin.

## Configure the plugin

```shell theme={null}
sudo tee /etc/strongswan.d/charon/pkcs11-futurex.conf \
  > /dev/null <<'EOF'
pkcs11 {
    load = yes
    modules {
        futurex {
            path = /usr/local/lib/libcryptohub-pkcs11.so
            os_locking = yes
            load_certs = no
        }
    }
}
EOF
```

Setting `load_certs = no` keeps certificates on the filesystem. The module name `futurex` must match the `module` value in `swanctl.conf`.

## Enable a charon log

```shell theme={null}
sudo tee /etc/strongswan.d/charon-logging.conf \
  > /dev/null <<'EOF'
charon {
    filelog {
        charon-debug {
            path = /var/log/charon-debug.log
            append = yes
            default = 2
            flush_line = yes
        }
    }
}
EOF

sudo systemctl restart strongswan-starter
```

## Verify module loading

```shell theme={null}
sudo grep -Ei \
  "loaded PKCS#11|found token|plugin 'pkcs11'" \
  /var/log/charon-debug.log | tail -20
```

<Check>
  The log reports the Futurex library, token slot 0, and a loaded PKCS #11 plugin. The measured library identifies itself to charon as PKCS #11 v3.2.
</Check>

The message `module 'futurex' does not support hot-plugging, canceled` does not block a statically configured endpoint.
