Re: Pam_pkcs11 ca_dir not working

Ludovic Rousseau <[email protected]>
Newsgroups gmane.comp.lib.muscle
Message-ID <CAGstE8BFp7YuomF+F7zOyMkAtrGXwoZbumbkOD8=SP9j2ERjSA@mail.gmail.com>
2014-04-12 12:21 GMT+02:00 Mario Di Ture <[email protected]>:
> Hi all,

Hello,

> I'm unable to authenticate sudo against a smart card when checking the CA.
> Sudo authenticates with SUCCESS with:
> cert_policy = signature;
> When I set:
> cert_policy = ca,signature;
> I get the error:
> ERROR:pkcs11_inspect.c:137: verify_certificate() failed: certificate is
> invalid: unable to get local issuer certificate
>
> Obviously, in the /etc/pam_pkcs11/cacerts there are the CA certificates in
> der and pem format (hash linked with pkcs11_make_hash_link).
>
> Thank you very much for your help.

You should activate the debug to know why you get "certificate is
invalid: unable to get local issuer certificate"
Look for "debug = " in your /etc/pam_pkcs11.conf file

Bye

-- 
 Dr. Ludovic Rousseau
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.