diff --git a/tasks/root_crt_creation.yml b/tasks/root_crt_creation.yml
index a5a093567da284ffd675a8d967ac5e088b8442c5..9eb220a607b8ed630c41cbc867ea92a25ab4ea45 100644
--- a/tasks/root_crt_creation.yml
+++ b/tasks/root_crt_creation.yml
@@ -9,7 +9,7 @@
     msg: "If the next task fails, then you need to decrypt the ansible vault."
 - name: create root certificate
   expect:
-    command: "openssl req -config {{root_ca_ini}} -engine pkcs11 -keyform engine -key {{root_ca_hsm_key[0].id}} -new -x509 -days 3650 -sha512 -extensions v3_ca -out {{root_ca_crt}}"
+    command: "openssl req -config {{root_ca_ini}} -engine pkcs11 -keyform engine -key {{root_ca_hsm_key.id}} -new -x509 -days 3650 -sha512 -extensions v3_ca -out {{root_ca_crt}}"
     responses: 
       Enter PKCS#11 token PIN: "{{hsm_pin}}"
     chdir: "{{ca_dir}}"