1
Go to the Endpoints menu for the service you deployed.
2
In the Manage Endpoints menu, select [ Add New ].
3
In the Add Endpoint dialog:
- Enter an identifier for the endpoint, or leave it empty for auto-generation.
- Confirm the CryptoHub Hostname field holds the address clients use to reach the CryptoHub. If CryptoHub auto-populates it, leave the value as is. If the field is empty, enter the CryptoHub FQDN or IP address yourself.
- Select the Platform for the endpoint.
Select the platform that matches the strongSwan host. The platform selection determines which build of
libfxpkcs11.so CryptoHub places in the zip, so a mismatch produces a library the host cannot load. This guide was validated on Ubuntu 24.04.4 with OpenSSL 3.0.13.4
Select [ Add Endpoint ]. The browser prompts you to download a zip file containing the Futurex PKCS #11 module, TLS certificates, and a configuration file preconfigured to connect to your CryptoHub instance.
The zip contains nine files:
PKCS11ManagerconfigTestlibfxpkcs11.sofxpkcs11.cfgclient-cert.pemclient.p12ca-chain.pemCryptoHub <serial>.cerFuturex Test Root CA (ECC).cerorFuturex Test Root SSL CA.cer
Confirm the endpoint role permissions
1
Go to the Identity and Access menu and select the Roles tab.
2
Find the role belonging to the endpoint you just created and open it for editing.
3
Confirm the permissions include
CertManage:Add, CertManage:Export, CertManage:Export Private Key, Crypto:Sign, Crypto:Verify, and Keys:Add.4
Save any changes.

