> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate charon can load the HSM-backed private key

> Load the filesystem certificate and CryptoHub token key into charon.

Load the responder certificate from the filesystem and its matching private key from CryptoHub.

## Install the certificates

```shell theme={null}
sudo install -d -m 755 /etc/swanctl/x509 /etc/swanctl/x509ca
sudo install -m 644 /root/strongswan-certs/responder-cert.pem \
  /etc/swanctl/x509/responder-cert.pem
sudo install -m 644 /root/strongswan-certs/ca-cert.pem \
  /etc/swanctl/x509ca/ca-cert.pem
```

## Configure the token credential

The following command reads the endpoint password and CKA\_ID from their protected files. It writes both values into the root-only strongSwan credential file without printing them.

```shell theme={null}
PIN="$(sudo cat /etc/strongswan-chlibs/token-pin)"
KEY_ID="$(sudo cat /etc/strongswan-chlibs/responder-key-id)"

sudo tee /etc/swanctl/swanctl.conf > /dev/null <<EOF
connections {
}

secrets {
    token-strongswan {
        module = futurex
        slot = 0
        handle = $KEY_ID
        pin = "$PIN"
    }
}
EOF

unset PIN KEY_ID
sudo chmod 600 /etc/swanctl/swanctl.conf
sudo chown root:root /etc/swanctl/swanctl.conf
```

<Warning>
  `swanctl.conf` contains the endpoint password. Restrict the file to root and exclude it from unprotected backups.
</Warning>

## Load the key

```shell theme={null}
sudo systemctl restart strongswan-starter
sudo swanctl --load-creds --clear --raw
```

<Check>
  The output includes `load-token reply {success=yes ...}`. The charon log includes `loaded RSA private key from token`.
</Check>

```shell theme={null}
sudo grep -Ei 'loaded RSA private key|load-token|futurex' \
  /var/log/charon-debug.log | tail -20
```
