Re: Pam_pkcs11 ca_dir not working

Mario Di Ture <[email protected]>
Newsgroups gmane.comp.lib.muscle
Message-ID <CAEN18r4h41z=7s1ONaDeJfdg8igpMNTKd=uR3JpDwGV14BhJfQ@mail.gmail.com>
But I cannot authenticate against smartcard with a valid certificate...
Il 12/apr/2014 16:00 "Ludovic Rousseau" <[email protected]> ha
scritto:

> 2014-04-12 14:53 GMT+02:00 Mario Di Ture <[email protected]>:
> > Ok, I attach the debug.
> > Note 1: on the card there are stored two certificates (one for signature,
> > another for logon) and only the second has the CA included.
> > Note 2: if I extract the logon certificate from the card and issue
> "openssl
> > verify -CApath /etc/pam_pkcs11/cacerts /home/mario/cert.cer" the result
> is
> > OK.
> > Mario
> >
> >
> > $ sudo -i
> > Smartcard authentication starts
> > DEBUG:pam_pkcs11.c:308: username = [mario]
> > DEBUG:pam_pkcs11.c:319: loading pkcs #11 module...
> > DEBUG:pkcs11_lib.c:975: PKCS #11 module = [/opt/libbit4xpki.so]
> > DEBUG:pkcs11_lib.c:992: module permissions: uid = 0, gid = 0, mode = 644
> > DEBUG:pkcs11_lib.c:1001: loading module /opt/libbit4xpki.so
> > DEBUG:pkcs11_lib.c:1009: getting function list
> > DEBUG:pam_pkcs11.c:334: initialising pkcs #11 module...
> > DEBUG:pkcs11_lib.c:1106: module information:
> > DEBUG:pkcs11_lib.c:1107: - version: 2.20
> > DEBUG:pkcs11_lib.c:1108: - manufacturer: bit4id srl
> > DEBUG:pkcs11_lib.c:1109: - flags: 0000
> > DEBUG:pkcs11_lib.c:1110: - library description: bit4id PKCS#11
> > DEBUG:pkcs11_lib.c:1111: - library version: 1.2
> > DEBUG:pkcs11_lib.c:1118: number of slots (a): 1
> > DEBUG:pkcs11_lib.c:1141: number of slots (b): 1
> > DEBUG:pkcs11_lib.c:1037: slot 1:
> > DEBUG:pkcs11_lib.c:1047: - description: ACS ACR 38U-CCID 00 00
> > DEBUG:pkcs11_lib.c:1048: - manufacturer: unknown
> > DEBUG:pkcs11_lib.c:1049: - flags: 0007
> > DEBUG:pkcs11_lib.c:1051: - token:
> > DEBUG:pkcs11_lib.c:1057:   - label: CNS
> > DEBUG:pkcs11_lib.c:1058:   - manufacturer: ST Incard
> > DEBUG:pkcs11_lib.c:1059:   - model: T&S DS/2048 (L)
> > DEBUG:pkcs11_lib.c:1060:   - serial: ***51090000***26
> > DEBUG:pkcs11_lib.c:1061:   - flags: 040d
> > Smart card found.
> > DEBUG:pkcs11_lib.c:1364: opening a new PKCS #11 session for slot 1
> > Welcome CNS!
> > Smart card PIN:
> > DEBUG:pkcs11_lib.c:1383: login as user CKU_USER
> > DEBUG:pkcs11_lib.c:1577: Saving Certificate #1:
> > DEBUG:pkcs11_lib.c:1579: - type: 00
> > DEBUG:pkcs11_lib.c:1580: - id:   44
> > DEBUG:pkcs11_lib.c:1577: Saving Certificate #2:
> > DEBUG:pkcs11_lib.c:1579: - type: 00
> > DEBUG:pkcs11_lib.c:1580: - id:   41
> > DEBUG:pkcs11_lib.c:1612: Found 2 certificates in token
> > DEBUG:mapper_mgr.c:172: Retrieveing mapper module list
> > DEBUG:mapper_mgr.c:73: Loading static module for mapper 'pwent'
> > DEBUG:mapper_mgr.c:196: Inserting mapper [pwent] into list
> > DEBUG:pam_pkcs11.c:551: verifying the certificate #1
> > verifying certificate
> > DEBUG:cert_vfy.c:338: Adding hashdir lookup to x509_store
> > DEBUG:cert_vfy.c:350: Adding hash dir '/etc/pam_pkcs11/cacerts' to CACERT
> > checks
> > ERROR:pam_pkcs11.c:559: verify_certificate() failed: certificate is
> invalid:
> > unable to get local issuer certificate
> > Error 2328: Certificate signature invalid
>
> Error 2328 corresponds to verify_certificate() returning -4 which
> corresponds to X509_verify_cert() returning
> X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY
>
> I don't know what is wrong.
>
> Bye
>
> --
>  Dr. Ludovic Rousseau
>
> _______________________________________________
> Muscle mailing list
> [email protected]
> http://lists.musclecard.com/mailman/listinfo/muscle_lists.musclecard.com
>

_______________________________________________
Muscle mailing list
[email protected]
http://lists.musclecard.com/mailman/listinfo/muscle_lists.musclecard.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.