Error importing PKCS#11 URL ... PKCS #11 error in device

William Boggs - NOAA Affiliate william.boggs at noaa.gov
Fri Jul 10 18:11:31 EDT 2020


Hi.

I'm working from home, and I am having trouble connecting to my work
VPN with my personal laptop.

>From the command line, I try to connect by openconnect using my CAC
reader and card. I am prompted for my PIN, but after I enter my PIN, I
receive this message:

************************************************

POST {DESTINATION}
Attempting to connect to server {IP ADDRESS}
Using PKCS#11 certificate
{PKCS#11 URL}
PIN required for {TOKEN}
Enter PIN:
Error importing PKCS#11 URL {PKCS#11}URL} PKCS #11 error in device
Loading certificate failed. Aborting.
Failed to open HTTPS connection to {DESTINATION}
Failed to obtain WebVPN cookie

************************************************
with identifying information replaced by {INFO} above.

Here's the command I used:

sudo openconnect -v -c {CERTIFICATE STRING} --cafile={SERVER
CERTIFICATE PATH} --no-dtls {DESTINATION}

with the same replacement.

What preceded this?

1) I was connected to the VPN successfully. I closed my laptop while
on battery, which started a suspend.
2) I stopped the suspend, but I was already disconnected.
3) I tried reconnecting, and I received the error.

I did not remove the CAC card in the steps above. I don't think that I
disconnected the CAC reader from the USB port on my laptop in the
steps above.

I rebooted my computer again, unplugged and plugged in the CAC card
reader, removed the CAC card and gently cleaned it off with a soft
cloth, but none of that helped.

I am running Ubuntu MATE 16.04.

I have a ticket with my work IT help desk, but I think that the
problem is on my end, and I am not optimistic about hearing back from
them, and then finding out that they can't help me since I am using my
personal laptop.

Thanks!



More information about the openconnect-devel mailing list