Skip to main content
Load the responder certificate from the filesystem and its matching private key from CryptoHub.

Install the certificates

Configure the token credential

The following command reads the endpoint password and CKA_ID from their protected files. It writes both values into the root-only strongSwan credential file without printing them.
swanctl.conf contains the endpoint password. Restrict the file to root and exclude it from unprotected backups.

Load the key

The output includes load-token reply {success=yes ...}. The charon log includes loaded RSA private key from token.