How to find out which process is accessing the card?
František Řezáč <[email protected]> Wed, 27 Sep 2017 21:58:25 +0200
| Newsgroups | gmane.comp.lib.muscle |
|---|---|
| Message-ID | <CAOe3-fbkWd4G0ckBaRk__gOoqDnnbittwzrm133NzTms8w301g@mail.gmail.com> |
--===============0597372465057971397== Content-Type: multipart/alternative; boundary="001a1138f342fe0b5c055a3136df" --001a1138f342fe0b5c055a3136df Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi, I'm using smart card for almost everything in my daily work, but I have a problem which drives me crazy. I'm using YubiKey in two scenarios: pkcs11 based PAM and SSH authentication and also as a GPG=E2=80=8E smart card. I understand that accesing one card via pkcs11 and scdaemon in turns is troubling, because GPG tends to lock the access to the card for itself full time, but I can handle that by manualy terminating scdaemon. But I have also come across the opossite situation many times - something locks access to the card via pkcs11 which prevents the access from scdaemon with the dreaded "PC/SC OPEN failed: sharing violation". The problem is that I don't know which process is using the card so I don't know how to deal with it except for restarting the whole pcscd. Also this problem seems to happen randomly so I don't have any clue if it's pam module or ssh agent or something else and it also randomly disappears. If I know what is using the card, I could try to configure it better or deal with it more gently. And that's my question - how to find out what is currently accessing/locking the card at a given time? I tried to figure it out myself, but after I have seen this schema https://blog.flameeyes.eu/2011/04/additional-notes-about-the-smartcard-comp= onents-diagram/ I realized that I don't even know at which level I should look for that information. -- Franti=C5=A1ek http://calavera.info/ --001a1138f342fe0b5c055a3136df Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hi,<div><br>I'm using smart card for almost everything= in my daily work, but I have a problem which drives me crazy. I'm usin= g YubiKey in two scenarios: pkcs11 based PAM and SSH authentication and als= o as a GPG=E2=80=8E smart card. I understand that accesing one card via pkc= s11 and scdaemon in turns is troubling, because GPG tends to lock the acces= s to the card for itself full time, but I can handle that by manualy termin= ating scdaemon.</div><div><br></div><div>But I have also come across the op= ossite situation many times - something locks access to the card via pkcs11= which prevents the access from scdaemon with the dreaded "PC/SC OPEN = failed: sharing violation". The problem is that I don't know which= process is using the card so I don't know how to deal with it except f= or restarting the whole pcscd. Also this problem seems to happen randomly s= o I don't have any clue if it's pam module or ssh agent or somethin= g else and it also randomly disappears. If I know what is using the card, I= could try to configure it better or deal with it more gently.</div><div><b= r></div><div>And that's my question - how to find out what is currently= accessing/locking the card at a given time? I tried to figure it out mysel= f, but after I have seen this schema=C2=A0<a href=3D"https://blog.flameeyes= .eu/2011/04/additional-notes-about-the-smartcard-components-diagram/">https= ://blog.flameeyes.eu/2011/04/additional-notes-about-the-smartcard-component= s-diagram/</a> I realized that I don't even know at which level I shoul= d look for that information.<br><br>--<br>Franti=C5=A1ek<br><a href=3D"http= ://calavera.info/">http://calavera.info/</a><br> </div></div> --001a1138f342fe0b5c055a3136df-- --===============0597372465057971397== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Pcsclite-muscle mailing list [email protected] http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pcsclite-muscle --===============0597372465057971397==--