> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create the responder key and certificates

> Create a CryptoHub-resident responder key and filesystem certificates for the IKEv2 peers.

Create the responder private key in CryptoHub, then issue filesystem certificates for both peers.

<Note>
  The CA commands below create a short-lived test CA. Use your organization's CA for production certificates. The responder certificate must contain the public key that matches the CryptoHub-resident private key.
</Note>

## Create the responder key

```shell theme={null}
sudo install -d -m 700 /root/strongswan-certs
KEY_ID="$(openssl rand -hex 8)"

sudo env CHLIBS_CONFIG=/etc/strongswan-chlibs/cryptohub.json \
  pkcs11-tool \
  --module /usr/local/lib/libcryptohub-pkcs11.so \
  --login \
  --pin "$(sudo cat /etc/strongswan-chlibs/token-pin)" \
  --keypairgen \
  --key-type rsa:2048 \
  --usage-sign \
  --label strongswan-responder \
  --id "$KEY_ID"

printf '%s\n' "$KEY_ID" \
  | sudo install -m 600 -o root -g root /dev/stdin \
      /etc/strongswan-chlibs/responder-key-id
unset KEY_ID
```

<Check>
  The output lists a private key with `Usage: sign` and a public key with `Usage: verify`. Both objects must have the same ID.
</Check>

## Export the public object

```shell theme={null}
KEY_ID="$(sudo cat /etc/strongswan-chlibs/responder-key-id)"

sudo env CHLIBS_CONFIG=/etc/strongswan-chlibs/cryptohub.json \
  pkcs11-tool \
  --module /usr/local/lib/libcryptohub-pkcs11.so \
  --login \
  --pin "$(sudo cat /etc/strongswan-chlibs/token-pin)" \
  --read-object \
  --type pubkey \
  --id "$KEY_ID" \
  --output-file /root/strongswan-certs/responder-public.der

unset KEY_ID
```

<Check>
  Run `sudo openssl pkey -pubin -inform DER -in /root/strongswan-certs/responder-public.der -noout`. The command must succeed.
</Check>

## Issue the certificates

```shell theme={null}
sudo -i
cd /root/strongswan-certs

pki --gen --type rsa --size 2048 --outform pem > ca-key.pem
pki --self --ca --lifetime 365 --in ca-key.pem --type rsa \
  --dn "CN=strongSwan example CA" --outform pem > ca-cert.pem

pki --issue --lifetime 30 \
  --in responder-public.der --type pub \
  --cacert ca-cert.pem --cakey ca-key.pem \
  --dn "CN=responder.example.com" \
  --san responder.example.com \
  --flag serverAuth --outform pem > responder-cert.pem

pki --gen --type rsa --size 2048 --outform pem > initiator-key.pem
pki --pub --in initiator-key.pem --type rsa \
  --outform der > initiator-public.der
pki --issue --lifetime 30 \
  --in initiator-public.der --type pub \
  --cacert ca-cert.pem --cakey ca-key.pem \
  --dn "CN=initiator.example.com" \
  --san initiator.example.com \
  --flag clientAuth --outform pem > initiator-cert.pem

pki --verify --in responder-cert.pem --cacert ca-cert.pem
pki --verify --in initiator-cert.pem --cacert ca-cert.pem
exit
```

<Check>
  Both verification commands report `certificate trusted, lifetimes valid`.
</Check>

No private-key file exists for the responder. Transfer `initiator-key.pem`, `initiator-cert.pem`, and `ca-cert.pem` to the initiator over an encrypted channel.
