Creating a PKCS#11 client certificate enables a PKCS#11 client to authenticate and establish a secure connection to the vault.
To create a PKCS#11 client certificate
- Log in to the Vault web GUI.
- From the left menu, select Security.
- Click + Create Certificate on the Security page.
- Complete the following fields on the Create Client Certificate page.
- Name: Enter a name for the certificate.
- Create For: Specify the owner of the certificate.
- Expiration: Select an expiration date based on your requirements.
The expiration date must be within three years.
- Certificate Signing Request (CSR): Click Browse to select the CSR you generated in Generating a Private Key and a CSR.
- Click Create. The client certificate you just created appears under the Client Certificates table on the Security page.
- In the row of the created certificate, click More Actions (vertical ellipsis icon) on the right.
- Select Download to download a bundle that contains
- A PEM user certificate and key file
- A PEM CA certificate
- Extract the bundle contents file.
- Save the user certificate and key files and the CA certificate to the same folder as the key and the CSR you generated in Generating a Private Key and a CSR.
You will need the user certificate and key files and the CA certificate to complete Configuring the PKCS#11 Vault client.