Re: certificates keys on pkcs11 devices

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



Hi,

I created a patch that allows to add ssh User Certificates to ssh-agent independent from the key.
This is useful when the private key is stored on a pkcs11 device.

the patch adds an option "-C [cert_file]" to ssh-add. The patch adds function to ssh-add to check if a an keypair exists in ssh-agent. If a keypair corresponds to the public key of cert_file the certificate is added to the ssh-agent.
If called with -d -C  "[cert_file]" the certificate is removed.
I added a "-v" Option to print debug messages.

usage:

ssh-add -s /usr/local/lib/opensc-pkcs11.so -C  ~/.ssh/mysmartcard-cert.pub

ssh-add -d  -C  ~/.ssh/mysmartcard-cert.pub

ssh-add -C  ~/.ssh/mysmartcard-other-cert.pub

ssh-add -d  -C mysmartcard-other-cert.pub

I hope this function makes sense to you.

Best wihses,
Manon



--On 28 December 2016 at 03:51:44 +0100 Manon Goo <lists@xxxxxxxx> wrote:

Hi,

I have not found any way to use a Certificate with ssh-agent when my Key
is stored on a pkcs11 device. I can add my key with

ssh-add -s /usr/local/lib/opensc-pkcs11.so

but

ssh-add -s /usr/local/lib/opensc-pkcs11.so ~/.ssh/mykey-cert.pub

does not add the certificate to my agent. As far as I undestand,  in
ssh-add.c line 580

	if (pkcs11provider != NULL) {
		if (update_card(agent_fd, !deleting, pkcs11provider) == -1)
			ret = 1;
		goto done;
	}

does not check for additional (certifcate)-files files on the command
line and update_card neither does.

Is there any intention to change this?

Thanks in alot,
Manon





_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev



Manon Goo
Dembach Goo Informatik GmbH & Co. KG
Hohenzollernring 72
D-50672 Köln

Tel.: +49 221 12095-211
Mobil: +49 151 12222781
Fax: +49 221 12095-220
E-Mail:manon.goo@xxxxxxxx

Support-Hotline: 0800 / 100 4323

Amtsgericht Köln HRA 22794, USt-IdNr.: DE242 159 527
Haftende Gesellschafterin: Dembach Goo Verwaltungsgesellschaft mbH
Deren Geschäftsführer: Andreas Dembach, Manon Goo
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev




[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux