load-token reports success=no
Confirm that the module path,CHLIBS_CONFIG service environment, token PIN, and CKA_ID match the endpoint and key.
CHLIBS_CONFIG, missing or incorrect PIN, and an unavailable CKA_ID all produce this failure family.
C_Login reports CKR_USER_ALREADY_LOGGED_IN
Remove the password fromcryptohub.json. Keep only the endpoint username and set pkcs11.check_already_logged_in to true. Supply the endpoint password only through the strongSwan token PIN.
pki rejects —cakey-type
strongSwan 5.9.13 does not implement--cakey-type. Remove that option and allow pki to infer the CA key type.
AppArmor hides the real failure
Inspect the kernel audit log:IKE_AUTH fails after the token key loads
Compare eachlocal.id with the subject or SAN in its certificate and with the peer’s remote.id. Then verify the CA certificate and traffic selectors on both gateways.
