[OpenVPN home] [Date Prev] [Date Index] [Date Next]
[OpenVPN mailing lists] [Thread Prev] [Thread Index] [Thread Next]
Google
 
Web openvpn.net

RE: [Openvpn-devel] openvpn - support PKCS#11 smartcards


  • Subject: RE: [Openvpn-devel] openvpn - support PKCS#11 smartcards
  • From: "Alon Bar-Lev" <alon.barlev@xxxxxxxxx>
  • Date: Tue, 13 Sep 2005 14:49:03 +0200

C. Ruiz, Ivan wrote:

>The problem is clearly on OpenSC pkcs#11 implementation, but with the
option --pkcs11-sign-mode
> you have included we can workarround it!

OK... So we can close this issue.

> I agree to drop support for OpenSC. The PKCS#11 approach works well with
OpenSC and it will
> broad the support for other PKCS#11-aware smartcards/libraries.

Great... So we continue with request to merge the PKCS#11 code into openvpn.

> Can the code check wether there's a PIN specified by the user before
calling pkcs11_openSession and
> give a message like "You need to specify a PIN to access the smartcard."?

OK... I've already added --pkcs11-protected-authentication in the last
patch... So if it is not given and there is no --askpass  - I will add a
failure.

One more task for me is to support more than one PKCS#11 provider... I will
do this in the next weekend.

Best Regards,
Alon Bar-Lev.


____________________________________________
Openvpn-devel mailing list
Openvpn-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/openvpn-devel