Re: Pam_pkcs11 ca_dir not working
Ludovic Rousseau <[email protected]>
| Newsgroups | gmane.comp.lib.muscle |
|---|---|
| Message-ID | <CAGstE8BFp7YuomF+F7zOyMkAtrGXwoZbumbkOD8=SP9j2ERjSA@mail.gmail.com> |
2014-04-12 12:21 GMT+02:00 Mario Di Ture <[email protected]>: > Hi all, Hello, > I'm unable to authenticate sudo against a smart card when checking the CA. > Sudo authenticates with SUCCESS with: > cert_policy = signature; > When I set: > cert_policy = ca,signature; > I get the error: > ERROR:pkcs11_inspect.c:137: verify_certificate() failed: certificate is > invalid: unable to get local issuer certificate > > Obviously, in the /etc/pam_pkcs11/cacerts there are the CA certificates in > der and pem format (hash linked with pkcs11_make_hash_link). > > Thank you very much for your help. You should activate the debug to know why you get "certificate is invalid: unable to get local issuer certificate" Look for "debug = " in your /etc/pam_pkcs11.conf file Bye -- Dr. Ludovic Rousseau