This page explains how to configure and verify the Entrust CSP PKCS#11 Vault client.
A Vault administrator must complete Vault creation, Vault service configuration, softcard management, and client-certificate issuance. Ask the Vault administrator for the connection details and certificate files required on this page.
Prerequisites
Before configuring the client, make sure you have completed the following tasks:
- Obtain the following information from the Vault administrator:
- Vault service hostname or IP address
- Vault service port
- CA certificate in PEM format
- Client certificate in PEM format
- Any required PKCS#11 login or token credentials
Ensure the private key corresponding to the CSR provided to the Vault administrator is available in PEM format.
- Install the CSP PKCS#11 Vault client using the Windows installer or the Linux tarball supplied with the product. The installation includes the PKCS#11 library, header files, and a configuration-file template.
Creating a client configuration file
The library reads its configuration from the following location:
/etc/cspp11/config.txt<PROGRAMDATA>\\Entrust\\cspp11\\config.txtThis can be overridden by setting the CSPP11CONFIG_PATH environment variable to the full path to the configuration file.
- Copy the configuration template to the default location, or choose a different location for the file.
- Set
CSPP11_CONFIG_PATHto the custom file path when using a non-default location. - Uncomment the required settings in the configuration file.
- Replace the example values with the values the Vault administrator supplies.
- Verify that the client certificate, private key, and CA certificate are readable by the application account.
- Protect the private-key file using the operating-system permissions appropriate for your environment.
The settings are:
Setting | Description | Mandatory |
|---|---|---|
port | Port used by the Vault service |
|
server_ip | Hostname or IP address of the CSP Vault node |
|
ca_cert_path | Path to the PEM-encoded CA certificate provided by the Vault |
|
client_cert_path | Path to the PEM-encoded client certificate provided by the Vault |
|
client_key_path | Path to the PEM-encoded private key corresponding to the client certificate |
|
log_file_path | Path to the client log file. If omitted, the client uses the platform-specific default |
|
log_level | The logging level:
|
|
See below for a configuration example:
# Entrust CSP PKCS#11 Vault client configurationport=10000server_ip=vault.example.comca_cert_path=/path/to/vault_cacert.pemclient_cert_path=/path/to/vault_client_cert.pemclient_key_path=/path/to/vault_client_key.pem# Optional settings# log_file_path=/path/to/client.log# log_level=INFOUse Windows paths when configuring the client on Windows. For example:
ca_cert_path=C:\ProgramData\Entrust\cspp11\vault_cacert.pemclient_cert_path=C:\ProgramData\Entrust\cspp11\vault_client_cert.pemclient_key_path=C:\ProgramData\Entrust\cspp11\vault_client_key.pemSetting a custom configuration path
Set the variable before starting the PKCS#11 application. To make the setting persistent, configure it using the operating system's environment-variable settings.
export CSPP11_CONFIG_PATH=/opt/entrust/cspp11/config.txtUsing the client library
Configure the application to load the CSP PKCS#11 library installed with the client. The library filename and installation path depend on the operating system and installation package.
Applications using the PKCS#11 standard can then initialize the library, enumerate available slots, open a session, and authenticate using the credentials provided by the Vault administrator. Application-specific configuration and login procedures are outside the scope of this guide.
If you are using a test or diagnostic program that supports dynamic library loading, provide the path to the CSP PKCS#11 library with that program's library option. For example:
ckinfo-dynamic --library /opt/entrust/cspp11/lib/libcspp11.soVerifying the configuration
After configuring the client:
- Confirm that the Vault hostname or IP address and port are reachable from the client host.
- Confirm that all certificate and key paths are correct.
- Confirm that the private key corresponds to the client certificate.
- Start a PKCS#11 application or diagnostic tool.
- Verify that the application can initialize the library and enumerate the expected slot or token.
- Review the client log if the connection or initialization fails.
Troubleshooting
Issue | Solution |
|---|---|
The configuration file is not found | Verify that the file exists at the default path or that |
The client cannot connect to the Vault | Verify the server hostname or IP address, port, firewall rules, and network route. Review the client log for additional details. |
Certificate or key errors occur | Verify that the files are PEM-encoded, readable by the application account, and specified with the correct paths. Ask the Vault administrator to confirm the client certificate is valid and that the configured private key matches that certificate. |
No slot or token is displayed | Verify that the PKCS#11 library loaded successfully and that the Vault service is available. If authentication is required, verify that the application is using the credentials or token PIN supplied by the Vault administrator. |
Security requirements
- Do not share the client private key or token credentials.
- Do not place private keys or credentials in source code or command history.
- Restrict access to the configuration file and certificate files according to your organization's security policy.
- Use
DEBUGlogging only for troubleshooting and return toWARNor the approved production level afterward. - Contact the Vault administrator when certificates expire, are revoked, or need replacement.