Hi,
I created a patch that allows to add ssh User Certificates to ssh-agent
independent from the key.
This is useful when the private key is stored on a pkcs11 device.
the patch adds an option "-C [cert_file]" to ssh-add. The patch adds
function to ssh-add to check if a an keypair exists in ssh-agent. If a
keypair corresponds to the public key of cert_file the certificate is added
to the ssh-agent.
If called with -d -C "[cert_file]" the certificate is removed.
I added a "-v" Option to print debug messages.
usage:
ssh-add -s /usr/local/lib/opensc-pkcs11.so -C ~/.ssh/mysmartcard-cert.pub
ssh-add -d -C ~/.ssh/mysmartcard-cert.pub
ssh-add -C ~/.ssh/mysmartcard-other-cert.pub
ssh-add -d -C mysmartcard-other-cert.pub
I hope this function makes sense to you.
Best wihses,
Manon
--On 28 December 2016 at 03:51:44 +0100 Manon Goo <lists@xxxxxxxx> wrote:
Hi,
I have not found any way to use a Certificate with ssh-agent when my Key
is stored on a pkcs11 device. I can add my key with
ssh-add -s /usr/local/lib/opensc-pkcs11.so
but
ssh-add -s /usr/local/lib/opensc-pkcs11.so ~/.ssh/mykey-cert.pub
does not add the certificate to my agent. As far as I undestand, in
ssh-add.c line 580
if (pkcs11provider != NULL) {
if (update_card(agent_fd, !deleting, pkcs11provider) == -1)
ret = 1;
goto done;
}
does not check for additional (certifcate)-files files on the command
line and update_card neither does.
Is there any intention to change this?
Thanks in alot,
Manon
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev
Manon Goo
Dembach Goo Informatik GmbH & Co. KG
Hohenzollernring 72
D-50672 Köln
Tel.: +49 221 12095-211
Mobil: +49 151 12222781
Fax: +49 221 12095-220
E-Mail:manon.goo@xxxxxxxx
Support-Hotline: 0800 / 100 4323
Amtsgericht Köln HRA 22794, USt-IdNr.: DE242 159 527
Haftende Gesellschafterin: Dembach Goo Verwaltungsgesellschaft mbH
Deren Geschäftsführer: Andreas Dembach, Manon Goo
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev