1
Go to the Endpoints menu for the service you deployed.
2
In the Manage Endpoints menu, select [ Add New ].
3
In the Add Endpoint dialog:
- Endpoint Identifier: Enter an identifier or leave it empty for auto-generation.
- CryptoHub Hostname: Leave the auto-populated value as is.
- Platform: Select Linux OpenSSL 3.x.
Select the platform that matches the OpenSSL version on the step-ca host. This guide was validated with Linux OpenSSL 3.x on Ubuntu 24.04.4 with OpenSSL 3.0.13. The platform selection determines which build of
libfxpkcs11.so CryptoHub places in the ZIP, so a mismatch produces a library the host cannot load.4
Select [ Add Endpoint ]. The browser prompts you to download a ZIP file containing the Futurex PKCS #11 module, TLS certificates, and a configuration file preconfigured to connect to your CryptoHub instance.
The ZIP contains nine files:
PKCS11ManagerconfigTestlibfxpkcs11.sofxpkcs11.cfgclient-cert.pemclient.p12ca-chain.pemCryptoHub <number>.cerFuturex Test Root CA (ECC).cerorFuturex Test Root SSL CA.cer

