Creating a PKCS#11 client certificate enables a PKCS#11 client to authenticate and establish a secure connection to the vault.

To create a PKCS#11 client certificate

  1. Log in to the Vault web GUI.
  2. From the left menu, select Security. 
  3. Click + Create Certificate on the Security page.
  4. Complete the following fields on the Create Client Certificate page.
    • Name: Enter a name for the certificate.
    • Create For: Specify the owner of the certificate.
    • Expiration: Select an expiration date based on your requirements.

      The expiration date must be within three years.

    • Certificate Signing Request (CSR): Click Browse to select the CSR you generated in Generating a Private Key and a CSR.
  5. Click Create. The client certificate you just created appears under the Client Certificates table on the Security page.
  6. In the row of the created certificate, click More Actions (vertical ellipsis icon) on the right.
  7. Select Download to download a bundle that contains
    • A PEM user certificate and key file
    • A PEM CA certificate
  8. Extract the bundle contents file.
  9. Save the user certificate and key files and the CA certificate to the same folder as the key and the CSR you generated in Generating a Private Key and a CSR.

    You will need the user certificate and key files and the CA certificate to complete Configuring the PKCS#11 Vault client.