Skip to main content
Create the responder private key in CryptoHub, then issue filesystem certificates for both peers.
The CA commands below create a short-lived test CA. Use your organization’s CA for production certificates. The responder certificate must contain the public key that matches the CryptoHub-resident private key.

Create the responder key

The output lists a private key with Usage: sign and a public key with Usage: verify. Both objects must have the same ID.

Export the public object

Run sudo openssl pkey -pubin -inform DER -in /root/strongswan-certs/responder-public.der -noout. The command must succeed.

Issue the certificates

Both verification commands report certificate trusted, lifetimes valid.
No private-key file exists for the responder. Transfer initiator-key.pem, initiator-cert.pem, and ca-cert.pem to the initiator over an encrypted channel.