read cert from smart card

Mithat Bozkurt mithatbozkurt at gmail.com
Sat Feb 20 11:35:55 PST 2016


Hello

However I read your html pages mentioned PKCS#11 I couldn't find a way
to use smart
card(ACS 38T) with openconnect.

My client certificate is in PKCS#11 compliance device and I couldn't
export it due
to it is e-signature cert.

I installed network-manager-openconnect-gnome and I see only the
following selection.
RSA SecureID read from ~/.stokenrc
RSA SecureID (manually entered)
TOTP (manually entered)
HOTP (manually entered)


Do I see PKCS#11 also?

output of "p11tool --list-tokens". There is no my token manufacturer.

mithat at adige:~$ p11tool --list-tokens
Token 0:
        URL:
pkcs11:model=p11-kit-trust;manufacturer=PKCS%2311%20Kit;serial=1;token=System%20Trust
        Label: System Trust
        Type: Trust module
        Manufacturer: PKCS#11 Kit
        Model: p11-kit-trust
        Serial: 1


Token 1:
        URL:
pkcs11:model=1.0;manufacturer=Gnome%20Keyring;serial=1%3aSSH%3aHOME;token=SSH%20Keys
        Label: SSH Keys
        Type: Generic token
        Manufacturer: Gnome Keyring
        Model: 1.0
        Serial: 1:SSH:HOME


Token 2:
        URL:
pkcs11:model=1.0;manufacturer=Gnome%20Keyring;serial=1%3aSECRET%3aMAIN;token=Secret%20Store
        Label: Secret Store
        Type: Generic token
        Manufacturer: Gnome Keyring
        Model: 1.0
        Serial: 1:SECRET:MAIN


Token 3:
        URL:
pkcs11:model=1.0;manufacturer=Gnome%20Keyring;serial=1%3aUSER%3aDEFAULT;token=Gnome2%20Key%20Storage
        Label: Gnome2 Key Storage
        Type: Generic token
        Manufacturer: Gnome Keyring
        Model: 1.0
        Serial: 1:USER:DEFAULT


Token 4:
        URL:
pkcs11:model=1.0;manufacturer=Gnome%20Keyring;serial=1%3aXDG%3aDEFAULT;token=User%20Key%20Storage
        Label: User Key Storage
        Type: Generic token
        Manufacturer: Gnome Keyring
        Model: 1.0
        Serial: 1:XDG:DEFAULT




And I can access my certificate for signing a document without any problem.

My system is ubuntu 15.10 64-bit.

Could you please help me?

Best regards.
Mithat Bozkurt



More information about the openconnect-devel mailing list