This page is intended for users, such as system administrators, who need to verify or integrate a client with CSP Vault for PKCS#11.

Client libraries

The CSP PKCS#11 Vault client package includes a dynamically loadable PKCS#11 library for each supported platform:

Platform

Library

Windows x86-64

cspp11.dll

Linux x86-64

libcspp11.so

The package also contains the header files required to build your own C program using the library.

The application must be able to locate the library installed by the client package. Applications may load the library using its full path or the library name if the installation location is included in the system library search path. 

  • On Windows, ensure that the directory containing cspp11.dll is available to the application through its library search path.
  • On Linux, provide the full path to libcspp11.so or add its directory to the system library search path as required by the application.

The client library reads the CSP Vault connection settings from its configuration file. For configuration instructions, see: Configuring the PKCS#11 Vault client.

Operational restrictions

Applications using the client must use serial sessions. Notification callbacks and asynchronous sessions are not supported. For the complete list of supported functions, see: Capabilities.

Verify the client connection

Use a PKCS#11 diagnostic tool that can dynamically load the PKCS#11 library by its path name to verify the connection. For example:

Linux
<diagnostic-tool> --library /path/to/libcspp11.so


Windows Powershell
<diagnostic-tool>.exe --library 'C:\Path\To\cspp11.dll'

Use the diagnostic tool's help option to confirm the exact command-line syntax. A successful diagnostic should initialize the library and display information about the available slots, tokens, or mechanisms.

Troubleshoot connection problems

If the diagnostic tool cannot initialize the library or does not display the expected slot or token:

  • Confirm the application loads the correct library for the operating system and architecture.
  • Confirm that the client configuration file exists at the expected path or that CSPP11_CONFIG_PATH it points to the correct file.
  • Confirm the Vault address, port, CA certificate, client certificate, and private-key paths in the configuration file.
  • Confirm that the application account can read the certificate and private-key files.
  • Confirm network connectivity and firewall access to the Vault service.
  • Confirm that the client certificate is valid and that its private key matches the certificate.
  • Review the client log for additional information.

Errors that occur before the client reads its configuration are written to standard error. For log locations, logging levels, and server logs, see: Logging.