<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[Форум Рутокен &mdash; Проблема с engine_pkcs11 и openssl.cnf]]></title>
	<link rel="self" href="https://forum.rutoken.ru/feed/atom/topic/1456" />
	<updated>2011-04-25T13:10:51Z</updated>
	<generator>PunBB</generator>
	<id>https://forum.rutoken.ru/topic/1456/</id>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3610/#p3610" />
			<content type="html"><![CDATA[<p>Нет, не проводил - провел и все ОК заработало :) Спасибо!</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-25T13:10:51Z</updated>
			<id>https://forum.rutoken.ru/post/3610/#p3610</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3605/#p3605" />
			<content type="html"><![CDATA[<p>Добрый день.</p><p>Производили ли Вы первоначальную инициализацию токена, как описано здесь? <br /><a href="http://www.opensc-project.org/opensc/wiki/AktivRutokenECP">http://www.opensc-project.org/opensc/wi … RutokenECP</a> ?</p>]]></content>
			<author>
				<name><![CDATA[Кирилл Мещеряков]]></name>
				<uri>https://forum.rutoken.ru/user/6786/</uri>
			</author>
			<updated>2011-04-25T07:20:22Z</updated>
			<id>https://forum.rutoken.ru/post/3605/#p3605</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3602/#p3602" />
			<content type="html"><![CDATA[<p>OpenSSL:</p><p>Если идти по официальному руководству <a href="http://www.opensc-project.org/opensc/wiki/QuickStart">http://www.opensc-project.org/opensc/wiki/QuickStart</a> то.....<br />root@Serverstation:~# openssl<br />OpenSSL&gt; engine dynamic -pre SO_PATH:/usr/lib/engines/engine_pkcs11.so -pre ID:pkcs11 -pre LIST_ADD:1 -pre LOAD -pre MODULE_PATH:opensc-pkcs11.so<br />(dynamic) Dynamic engine loading support<br />[Success]: SO_PATH:/usr/lib/engines/engine_pkcs11.so<br />[Success]: ID:pkcs11<br />[Success]: LIST_ADD:1<br />[Success]: LOAD<br />[Success]: MODULE_PATH:opensc-pkcs11.so<br />Loaded: (pkcs11) pkcs11 engine<br />OpenSSL&gt; version<br />OpenSSL 1.1.0-dev xx XXX xxxx</p><p>НО - любая дальнейшая операция заканчивается висением до того момента как мы нажмем Ctrl-C</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-24T22:59:10Z</updated>
			<id>https://forum.rutoken.ru/post/3602/#p3602</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3601/#p3601" />
			<content type="html"><![CDATA[<p>#pcscd -df</p><br /><p>19856305 hotplug_libusb.c:503:HPAddHotPluggable() Adding USB device: 3:44:0<br />00000034 readerfactory.c:934:RFInitializeReader() Attempting startup of Aktiv Rutoken ECP 00 00 using /usr/lib64/pcsc/drivers/ifd-ccid.bundle/Contents/Linux/libccid.so<br />00019344 readerfactory.c:824:RFBindFunctions() Loading IFD Handler 3.0<br />00000049 ifdhandler.c:1732:init_driver() Driver version: 1.4.3<br />00001011 ifdhandler.c:1750:init_driver() LogLevel: 0x0003<br />00000014 ifdhandler.c:1771:init_driver() DriverOptions: 0x0000<br />00000121 ifdhandler.c:79:IFDHCreateChannelByName() lun: 0, device: usb:0a89/0030:libusb-1.0:3:44:0<br />00000931 ccid_usb.c:245:OpenUSBByName() ifdManufacturerString: Ludovic Rousseau (ludovic.rousseau@free.fr)<br />00000012 ccid_usb.c:246:OpenUSBByName() ifdProductString: Generic CCID driver<br />00000008 ccid_usb.c:247:OpenUSBByName() Copyright: This driver is protected by terms of the GNU Lesser General Public License version 2.1, or (at your option) any later version.<br />00020999 ccid_usb.c:486:OpenUSBByName() Found Vendor/Product: 0A89/0030 (Aktiv Rutoken ECP)<br />00000015 ccid_usb.c:488:OpenUSBByName() Using USB bus/device: 3/44<br />00000312 ccid_usb.c:918:get_data_rates() IFD does not support GET_DATA_RATES request: -9<br />00004047 ifdhandler.c:401:IFDHGetCapabilities() tag: 0xFB3, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000024 readerfactory.c:290:RFAddReader() Using the pcscd polling thread<br />00003997 ifdhandler.c:401:IFDHGetCapabilities() tag: 0xFAE, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000023 ifdhandler.c:489:IFDHGetCapabilities() Reader supports 1 slot(s)<br />00007904 ifdhandler.c:1151:IFDHPowerICC() action: PowerUp, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00004011 eventhandler.c:256:EHStatusHandlerThread() powerState: POWER_STATE_POWERED<br />00000016 Card ATR: 3B 8B 01 52 75 74 6F 6B 65 6E 20 44 53 20 C1<br />00406967 ifdhandler.c:1151:IFDHPowerICC() action: PowerDown, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00003997 eventhandler.c:446:EHStatusHandlerThread() powerState: POWER_STATE_UNPOWERED</p><p>токен он видит - уже хорошо.&nbsp; Продолжаем :</p><p># opensc-explorer -vv<br />OpenSC Explorer version 0.12.1-svn<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] sc.c:185:sc_detect_card_presence: called<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] reader-pcsc.c:366:pcsc_detect_card_presence: returning with: 1<br />Using reader with a card: Aktiv Rutoken ECP 00 00<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] sc.c:185:sc_detect_card_presence: called<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] reader-pcsc.c:366:pcsc_detect_card_presence: returning with: 1<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] card.c:115:sc_connect_card: called<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] card-rtecp.c:91:rtecp_init: returning with: 0 (Success)<br />0x7fc4a27fc700 02:43:22.719 [opensc-explorer] apdu.c:524:sc_transmit_apdu: called<br />0x7fc4a27fc700 02:43:22.723 [opensc-explorer] iso7816.c:478:iso7816_select_file: returning with: -1201 (File not found)<br />0x7fc4a27fc700 02:43:22.723 [opensc-explorer] card-rtecp.c:268:rtecp_select_file: returning with: -1201 (File not found)<br />unable to select MF: File not found</p><br /><p>вывод демона :</p><p>95580956 winscard_msg_srv.c:202:ProcessEventsServer() Common channel packet arrival<br />00000027 winscard_msg_srv.c:214:ProcessEventsServer() ProcessCommonChannelRequest detects: 13<br />00000008 pcscdaemon.c:91:SVCServiceRunLoop() A new context thread creation is requested: 13<br />00000099 winscard_svc.c:297:ContextThread() Thread is started: dwClientID=13, threadContext @13FB280<br />00000093 winscard_svc.c:315:ContextThread() Received command: CMD_VERSION from client 13<br />00000015 winscard_svc.c:327:ContextThread() Client is protocol version 4:2<br />00000008 winscard_svc.c:347:ContextThread() CMD_VERSION rv=0x0 for client 13<br />00000044 winscard_svc.c:315:ContextThread() Received command: ESTABLISH_CONTEXT from client 13<br />00000017 winscard.c:193:SCardEstablishContext() Establishing Context: 0x1034989<br />00000007 winscard_svc.c:406:ContextThread() ESTABLISH_CONTEXT rv=0x0 for client 13<br />00000041 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000033 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000101 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000173 winscard_svc.c:315:ContextThread() Received command: CONNECT from client 13<br />00000013 winscard.c:235:SCardConnect() Attempting Connect to Aktiv Rutoken ECP 00 00 using protocol: 3<br />00002221 ifdhandler.c:1151:IFDHPowerICC() action: PowerUp, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00003991 winscard.c:309:SCardConnect() power up complete.<br />00000025 Card ATR: 3B 8B 01 52 75 74 6F 6B 65 6E 20 44 53 20 C1<br />00000008 winscard.c:328:SCardConnect() powerState: POWER_STATE_INUSE<br />00000015 prothandler.c:127:PHSetProtocol() Attempting PTS to T=1<br />00000015 ifdhandler.c:700:IFDHSetProtocolParameters() protocol T=1, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000009 winscard.c:406:SCardConnect() Active Protocol: T=1<br />00000009 winscard.c:426:SCardConnect() hCard Identity: 177cb<br />00000012 winscard_svc.c:447:ContextThread() CONNECT rv=0x0 for client 13<br />00000244 winscard_svc.c:315:ContextThread() Received command: CONTROL from client 13<br />00000021 ifdhandler.c:1323:IFDHControl() ControlCode: 0x42000D48, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000009 Control TxBuffer:<br />00000015 Control RxBuffer: 0A 04 42 33 00 0A 12 04 42 33 00 12<br />00000007 winscard_svc.c:646:ContextThread() CONTROL rv=0x0 for client 13<br />00000087 winscard_svc.c:315:ContextThread() Received command: CONTROL from client 13<br />00000018 ifdhandler.c:1323:IFDHControl() ControlCode: 0x4233000A, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000006 Control TxBuffer:<br />00000007 Control RxBuffer: 00 00 07 00<br />00000006 winscard_svc.c:646:ContextThread() CONTROL rv=0x0 for client 13<br />00000055 winscard_svc.c:315:ContextThread() Received command: DISCONNECT from client 13<br />00000020 winscard.c:826:SCardDisconnect() Active Contexts: 1<br />00000006 winscard.c:827:SCardDisconnect() dwDisposition: 0<br />00000008 winscard.c:992:SCardDisconnect() powerState: POWER_STATE_GRACE_PERIOD<br />00000007 ifdhandler.c:401:IFDHGetCapabilities() tag: 0xFB2, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000008 winscard_svc.c:484:ContextThread() DISCONNECT rv=0x0 for client 13<br />00000099 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000046 winscard_svc.c:315:ContextThread() Received command: CMD_WAIT_READER_STATE_CHANGE from client 13<br />00000023 winscard_svc.c:315:ContextThread() Received command: CMD_STOP_WAITING_READER_STATE_CHANGE from client 13<br />00000017 winscard_svc.c:387:ContextThread() CMD_STOP_WAITING_READER_STATE_CHANGE rv=0x0 for client 13<br />00000025 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000178 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000061 winscard_svc.c:315:ContextThread() Received command: CMD_WAIT_READER_STATE_CHANGE from client 13<br />00000019 winscard_svc.c:315:ContextThread() Received command: CMD_STOP_WAITING_READER_STATE_CHANGE from client 13<br />00000013 winscard_svc.c:387:ContextThread() CMD_STOP_WAITING_READER_STATE_CHANGE rv=0x0 for client 13<br />00000131 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000180 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000043 winscard_svc.c:315:ContextThread() Received command: CMD_WAIT_READER_STATE_CHANGE from client 13<br />00000019 winscard_svc.c:315:ContextThread() Received command: CMD_STOP_WAITING_READER_STATE_CHANGE from client 13<br />00000014 winscard_svc.c:387:ContextThread() CMD_STOP_WAITING_READER_STATE_CHANGE rv=0x0 for client 13<br />00000029 winscard_svc.c:315:ContextThread() Received command: CMD_GET_READERS_STATE from client 13<br />00000126 winscard_svc.c:315:ContextThread() Received command: CONNECT from client 13<br />00000013 winscard.c:235:SCardConnect() Attempting Connect to Aktiv Rutoken ECP 00 00 using protocol: 3<br />00000007 winscard.c:328:SCardConnect() powerState: POWER_STATE_INUSE<br />00000006 winscard.c:406:SCardConnect() Active Protocol: T=1<br />00000008 winscard.c:426:SCardConnect() hCard Identity: 16213<br />00000007 winscard_svc.c:447:ContextThread() CONNECT rv=0x0 for client 13<br />00000564 winscard_svc.c:315:ContextThread() Received command: BEGIN_TRANSACTION from client 13<br />00000162 winscard.c:1057:SCardBeginTransaction() Status: 0x00000000<br />00000008 winscard_svc.c:499:ContextThread() BEGIN_TRANSACTION rv=0x0 for client 13<br />00000155 winscard_svc.c:315:ContextThread() Received command: TRANSMIT from client 13<br />00000024 winscard.c:1551:SCardTransmit() Send Protocol: T=1<br />00000009 ifdhandler.c:1280:IFDHTransmitToICC() usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00003407 winscard_svc.c:602:ContextThread() TRANSMIT rv=0x0 for client 13<br />00000617 winscard_svc.c:307:ContextThread() Client die: 13<br />00000020 winscard.c:204:SCardReleaseContext() Releasing Context: 0x1034989<br />00000013 winscard.c:826:SCardDisconnect() Active Contexts: 1<br />00000005 winscard.c:827:SCardDisconnect() dwDisposition: 1<br />00002346 ifdhandler.c:1151:IFDHPowerICC() action: Reset, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00003990 winscard.c:893:SCardDisconnect() Reset complete.<br />00000025 Card ATR: 3B 8B 01 52 75 74 6F 6B 65 6E 20 44 53 20 C1<br />00000010 winscard.c:992:SCardDisconnect() powerState: POWER_STATE_GRACE_PERIOD<br />00000008 ifdhandler.c:401:IFDHGetCapabilities() tag: 0xFB2, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00000010 winscard_svc.c:916:MSGCleanupClient() Thread is stopping: dwClientID=13, threadContext @13FB280<br />00000008 winscard_svc.c:922:MSGCleanupClient() Freeing SCONTEXT @13FB280<br />00311984 eventhandler.c:458:EHStatusHandlerThread() powerState: POWER_STATE_POWERED<br />00405923 ifdhandler.c:1151:IFDHPowerICC() action: PowerDown, usb:0a89/0030:libusb-1.0:3:44:0 (lun: 0)<br />00003987 eventhandler.c:446:EHStatusHandlerThread() powerState: POWER_STATE_UNPOWERED</p><p>OpenSSL :</p><p> #openssl engine -v -t<br />(aesni) Intel AES-NI engine (no-aesni)<br />&nbsp; &nbsp; &nbsp;[ available ]<br />(dynamic) Dynamic engine loading support<br />&nbsp; &nbsp; &nbsp;[ unavailable ]<br />&nbsp; &nbsp; &nbsp;SO_PATH, NO_VCHECK, ID, LIST_ADD, DIR_LOAD, DIR_ADD, LOAD<br />(pkcs11) pkcs11 engine</p><p>но... немного смущает то, что для PKCS#11 модуля нет ни строчки описания....</p><p>далее дело и тело пока не сдвинулись...<br />Единственная комманда, которая, как мне кажется, корректно отрабатывает :<br />#pkcs15-init -E -p rutoken<br />токен мигает и подает признаки жизни......</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-24T22:49:34Z</updated>
			<id>https://forum.rutoken.ru/post/3601/#p3601</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3598/#p3598" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>MidNight^er пишет:</cite><blockquote><p>По линку я нашёл обсуждение подобной проблемы и вроде как её частичное решение.. Но пока не моуг разобраться мой ли это случай.<br /><a href="http://www.opensc-project.org/pipermail/opensc-devel/2010-April/013953.html">http://www.opensc-project.org/pipermail … 13953.html</a> Патч что там предлагают меня не спас.</p></blockquote></div><p>Тот патч уже не актуален - код изменен.</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-22T11:26:49Z</updated>
			<id>https://forum.rutoken.ru/post/3598/#p3598</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3597/#p3597" />
			<content type="html"><![CDATA[<p>Если вытащить токен - вот что выдают комманды :</p><p>root@Serverstation:/home/epodbot/openct-0.6.20# pkcs11-tool -L<br />Available slots:<br />Slot 0 (0xffffffffffffffff): Virtual hotplug slot<br />&nbsp; (empty)<br />root@Serverstation:/home/epodbot/openct-0.6.20# pkcs11-tool -I<br />Cryptoki version 2.20<br />Manufacturer&nbsp; &nbsp; &nbsp;OpenSC (<a href="http://www.opensc-project.org">www.opensc-project.org</a>)<br />Library&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Smart card PKCS#11 API (ver 0.0)<br />No slot with a token was found.<br />root@Serverstation:/home/epodbot/openct-0.6.20# pkcs11-tool -T<br />Available slots:<br />No slots.</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-21T22:38:54Z</updated>
			<id>https://forum.rutoken.ru/post/3597/#p3597</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3596/#p3596" />
			<content type="html"><![CDATA[<p>pkcs11-tool -L<br />pkcs11-tool -I<br />pkcs11-tool -T</p><p>тоже виснем насмерть до ^C</p><p>PIN вбил в конфиг OpenSSL - no result</p><p>root@Serverstation:/etc/ssl# openssl version<br />OpenSSL 1.1.0-dev xx XXX xxxx</p><p>он последний с CVS</p><p>Библиотеки тоже, собралось все ОК, OpenCT при этом ест все замечательно :</p><p>root@Serverstation:/etc/ssl# opensc-tool --serial -Dl<br /># Detected readers (pcsc)<br />Nr.&nbsp; Card&nbsp; Features&nbsp; Name<br />0&nbsp; &nbsp; Yes&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Aktiv Rutoken ECP 00 00<br />Configured card drivers:<br />&nbsp; cardos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Siemens CardOS<br />&nbsp; flex&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Schlumberger Multiflex/Cryptoflex<br />&nbsp; cyberflex&nbsp; &nbsp; &nbsp; &nbsp; Schlumberger Cyberflex<br />&nbsp; gpk&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Gemplus GPK<br />&nbsp; gemsafeV1&nbsp; &nbsp; &nbsp; &nbsp; driver for the Gemplus GemSAFE V1 applet<br />&nbsp; miocos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;MioCOS 1.1<br />&nbsp; mcrd&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;MICARDO 2.1 / EstEID 1.0 - 3.0<br />&nbsp; asepcos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Athena ASEPCOS<br />&nbsp; starcos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; STARCOS SPK 2.3/2.4<br />&nbsp; tcos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TCOS 3.0<br />&nbsp; openpgp&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; OpenPGP card<br />&nbsp; jcop&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;JCOP cards with BlueZ PKCS#15 applet<br />&nbsp; oberthur&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Oberthur AuthentIC.v2/CosmopolIC.v4<br />&nbsp; belpic&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Belpic cards<br />&nbsp; ias&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; IAS<br />&nbsp; incrypto34&nbsp; &nbsp; &nbsp; &nbsp;Incard Incripto34<br />&nbsp; acos5&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ACS ACOS5 card<br />&nbsp; akis&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TUBITAK UEKAE AKIS<br />&nbsp; entersafe&nbsp; &nbsp; &nbsp; &nbsp; entersafe<br />&nbsp; rutoken&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Rutoken driver<br />&nbsp; rutoken_ecp&nbsp; &nbsp; &nbsp; Rutoken ECP driver<br />&nbsp; westcos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; WESTCOS compatible cards<br />&nbsp; myeid&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; MyEID cards with PKCS#15 applet<br />&nbsp; setcos&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Setec cards<br />&nbsp; muscle&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;MuscleApplet<br />&nbsp; atrust-acos&nbsp; &nbsp; &nbsp; A-Trust ACOS cards<br />&nbsp; piv&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; PIV-II&nbsp; for multiple cards<br />&nbsp; itacns&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Italian CNS<br />&nbsp; javacard&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;JavaCard (without supported applet)<br />&nbsp; default&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Default driver for unknown cards<br />Using reader with a card: Aktiv Rutoken ECP 00 00<br />00 00 00 00 2A 31 78 55 ....*1xU</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-21T19:09:14Z</updated>
			<id>https://forum.rutoken.ru/post/3596/#p3596</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3595/#p3595" />
			<content type="html"><![CDATA[<p>root@Serverstation:/etc/ssl# cat openssl.cnf<br />openssl_conf = openssl_def</p><p>[openssl_def]<br />engines = engine_section</p><p>[engine_section]<br />pkcs11 = pkcs11_section</p><p>[pkcs11_section]<br />engine_id = pkcs11<br />dynamic_path = /usr/lib/engines/engine_pkcs11.so<br />MODULE_PATH = /usr/lib/opensc-pkcs11.so<br />init = 0</p><p>root@Serverstation:/etc/ssl# uname -a<br />Linux Serverstation 2.6.35.10-greyplace #1 SMP Sat Jan 29 04:12:07 MSK 2011 x86_64 GNU/Linux</p><p>Ubuntu 10.10 x64 </p><p>root@Serverstation:/etc/ssl# openssl engine -v -t<br />(aesni) Intel AES-NI engine (no-aesni)<br />&nbsp; &nbsp; &nbsp;[ available ]<br />(dynamic) Dynamic engine loading support<br />&nbsp; &nbsp; &nbsp;[ unavailable ]<br />&nbsp; &nbsp; &nbsp;SO_PATH, NO_VCHECK, ID, LIST_ADD, DIR_LOAD, DIR_ADD, LOAD<br />(pkcs11) pkcs11 engine<br />&lt;виснем&gt;<br />^C</p>]]></content>
			<author>
				<name><![CDATA[ss666]]></name>
				<uri>https://forum.rutoken.ru/user/7730/</uri>
			</author>
			<updated>2011-04-21T18:48:50Z</updated>
			<id>https://forum.rutoken.ru/post/3595/#p3595</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3257/#p3257" />
			<content type="html"><![CDATA[<p>По линку я нашёл обсуждение подобной проблемы и вроде как её частичное решение.. Но пока не моуг разобраться мой ли это случай.<br /><a href="http://www.opensc-project.org/pipermail/opensc-devel/2010-April/013953.html">http://www.opensc-project.org/pipermail … 13953.html</a> Патч что там предлагают меня не спас.</p>]]></content>
			<author>
				<name><![CDATA[MidNight^er]]></name>
				<uri>https://forum.rutoken.ru/user/7571/</uri>
			</author>
			<updated>2010-12-19T15:39:45Z</updated>
			<id>https://forum.rutoken.ru/post/3257/#p3257</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Проблема с engine_pkcs11 и openssl.cnf]]></title>
			<link rel="alternate" href="https://forum.rutoken.ru/post/3255/#p3255" />
			<content type="html"><![CDATA[<p>Здравствуйте. Никак не получается завести&nbsp; engine_pkcs11 c openssl конфигом. Выдаёт кучу ошибок, может кто чего подскажет.</p><p>Версии ПО</p><div class="codebox"><pre><code>[root@localhost dev]# rpm -qa | grep engine_pkcs11
engine_pkcs11-0.1.8-1.fc14.x86_64
[root@localhost dev]# rpm -qa | grep openssl
openssl-devel-1.0.0c-1.fc14.x86_64
openssl-1.0.0c-1.fc14.x86_64</code></pre></div><p>OC Fedora 14 x86_64</p><p>Проверяем возможность работы engine_pkcs11 с openssl</p><div class="codebox"><pre><code>[midnighter@localhost ~]$ openssl
OpenSSL&gt; engine dynamic -pre
SO_PATH:/usr/lib64/openssl/engines/engine_pkcs11.so -pre ID:pkcs11 -pre
LIST_ADD:1 -pre LOAD -pre MODULE_PATH:engine_pkcs11.so
(dynamic) Dynamic engine loading support
[Success]: SO_PATH:/usr/lib64/openssl/engines/engine_pkcs11.so
[Success]: ID:pkcs11
[Success]: LIST_ADD:1
[Success]: LOAD
[Success]: MODULE_PATH:engine_pkcs11.so
Loaded: (pkcs11) pkcs11 engine
OpenSSL&gt;</code></pre></div><p>Редактируем файл конфигурации openssl</p><div class="codebox"><pre><code>[root@localhost dev]# vi /etc/pki/tls/openssl.cnf</code></pre></div><p>Убираем всё что там есть и пишем</p><div class="codebox"><pre><code>openssl_conf = openssl_def

[openssl_def]
engines = engine_section

[engine_section]
pkcs11 = pkcs11_section

[pkcs11_section]
engine_id = pkcs11
dynamic_path = /usr/lib64/openssl/engines/engine_pkcs11.so
MODULE_PATH = /usr/lib64/pkcs11/opensc-pkcs11.so
init = 0

[req]
distinguished_name = req_distinguished_name

[req_distinguished_name]</code></pre></div><p>В ответ получаем</p><div class="codebox"><pre><code>[root@localhost dev]# openssl engine -v -t
(aesni) Intel AES-NI engine (no-aesni)
     [ available ]
(dynamic) Dynamic engine loading support
     [ unavailable ]
     SO_PATH, NO_VCHECK, ID, LIST_ADD, DIR_LOAD, DIR_ADD, LOAD
(pkcs11) pkcs11 engine
openssl (lock_dbg_cb): already locked (mode=9, type=30) at eng_list.c:284
Auto configuration failed
139977877768000:error:26078067:engine routines:ENGINE_LIST_ADD:conflicting
engine id:eng_list.c:116:
139977877768000:error:2606906E:engine routines:ENGINE_add:internal list
error:eng_list.c:288:
139977877768000:error:260B6067:engine routines:DYNAMIC_LOAD:conflicting engine
id:eng_dyn.c:540:
139977877768000:error:260BC066:engine routines:INT_ENGINE_CONFIGURE:engine
configuration error:eng_cnf.c:204:section=pkcs11_section, name=dynamic_path,
value=/usr/lib64/openssl/engines/engine_pkcs11.so
139977877768000:error:0E07606D:configuration file routines:MODULE_RUN:module
initialization error:conf_mod.c:235:module=engines, value=engine_section,
retcode=-1      </code></pre></div><p>Такая же проблема у другого человека</p><p><a href="http://www.opensc-project.org/pipermail/opensc-user/2010-November/004330.html">http://www.opensc-project.org/pipermail … 04330.html</a></p><p>Я оформил проблему в багзиле <a href="https://bugzilla.redhat.com/show_bug.cgi?id=664160">https://bugzilla.redhat.com/show_bug.cgi?id=664160</a> но может тут кто уже сталкивался.</p>]]></content>
			<author>
				<name><![CDATA[MidNight^er]]></name>
				<uri>https://forum.rutoken.ru/user/7571/</uri>
			</author>
			<updated>2010-12-18T19:57:54Z</updated>
			<id>https://forum.rutoken.ru/post/3255/#p3255</id>
		</entry>
</feed>
