This page is intended for users, such as system administrators, who need to verify or integrate a client with CSP Vault for PKCS#11.
Client libraries
The CSP PKCS#11 Vault client package includes a dynamically loadable PKCS#11 library for each supported platform:
Platform | Library |
|---|---|
Windows x86-64 |
|
Linux x86-64 |
|
The package also contains the header files required to build your own C program using the library.
The application must be able to locate the library installed by the client package. Applications may load the library using its full path or the library name if the installation location is included in the system library search path.
- On Windows, ensure that the directory containing
cspp11.dllis available to the application through its library search path. - On Linux, provide the full path to
libcspp11.soor add its directory to the system library search path as required by the application.
The client library reads the CSP Vault connection settings from its configuration file. For configuration instructions, see: Configuring the PKCS#11 Vault client.
Operational restrictions
Applications using the client must use serial sessions. Notification callbacks and asynchronous sessions are not supported. For the complete list of supported functions, see: Capabilities.
Verify the client connection
Use a PKCS#11 diagnostic tool that can dynamically load the PKCS#11 library by its path name to verify the connection. For example:
<diagnostic-tool> --library /path/to/libcspp11.so<diagnostic-tool>.exe --library 'C:\Path\To\cspp11.dll'Use the diagnostic tool's help option to confirm the exact command-line syntax. A successful diagnostic should initialize the library and display information about the available slots, tokens, or mechanisms.
Troubleshoot connection problems
If the diagnostic tool cannot initialize the library or does not display the expected slot or token:
- Confirm the application loads the correct library for the operating system and architecture.
- Confirm that the client configuration file exists at the expected path or that
CSPP11_CONFIG_PATHit points to the correct file. - Confirm the Vault address, port, CA certificate, client certificate, and private-key paths in the configuration file.
- Confirm that the application account can read the certificate and private-key files.
- Confirm network connectivity and firewall access to the Vault service.
- Confirm that the client certificate is valid and that its private key matches the certificate.
- Review the client log for additional information.
Errors that occur before the client reads its configuration are written to standard error. For log locations, logging levels, and server logs, see: Logging.