Skip to main content
Install the endpoint download as one protected module, configuration, and TLS unit.

Install the endpoint files

Extract the endpoint ZIP and change to its extracted directory. Run:
Run test -x /usr/local/lib/libcryptohub-pkcs11.so and sudo test -r /etc/strongswan-chlibs/client.p12. Both commands must succeed.

Separate the UserPass password from the config

strongSwan calls PKCS #11 C_Login. Keep the endpoint username in cryptohub.json and deliver the endpoint password as the token PIN. Run these commands from the extracted endpoint directory:
Do not leave the password in the endpoint configuration and also configure it as the token PIN. That duplicate login state causes CKR_USER_ALREADY_LOGGED_IN when strongSwan loads the key.

Set the service environment

Run sudo systemctl show strongswan-starter -p Environment. The output must include the CHLIBS_CONFIG setting shown in the service drop-in.

Verify the module

The output lists the Futurex token in slot 0.