allow using label to differentiate multiple tokens in same slot
This commit is contained in:
parent
e4d31848fd
commit
c032498244
2 changed files with 24 additions and 1 deletions
|
|
@ -64,6 +64,19 @@ describe_cert() {
|
|||
echo "sha256 (apk_cert_sha256): $(sha256sum "$1" | cut -d' ' -f1)"
|
||||
}
|
||||
|
||||
# The label of the token in slot PKCS11_SLOT_INDEX, as pkcs11-tool numbers slots for
|
||||
# --slot-index.
|
||||
token_label() {
|
||||
pkcs11-tool --module "$module" --list-slots 2>/dev/null | awk -v n="$slot_index" '
|
||||
/^Slot [0-9]+ / { s = $2 }
|
||||
s == n && /^[[:space:]]*token label[[:space:]]*:/ { sub(/^[^:]*:[[:space:]]*/, ""); print; exit }'
|
||||
}
|
||||
|
||||
# $1 percent-encoded, every byte, for a pkcs11: URI (RFC 7512).
|
||||
uri_encode() {
|
||||
printf '%s' "$1" | od -An -v -tx1 | tr -d ' \n' | tr 'a-f' 'A-F' | sed 's/../%&/g'
|
||||
}
|
||||
|
||||
# SunPKCS11's configuration: which library, which slot.
|
||||
cat > "$work/pkcs11.cfg" <<EOF
|
||||
name = HSM
|
||||
|
|
@ -164,12 +177,19 @@ distinguished_name = dn
|
|||
[dn]
|
||||
EOF
|
||||
uri_id="$(printf '%s' "$key_id" | sed 's/../%&/g')"
|
||||
# The key's URI names its token: an OpenPGP card shows up as two tokens (User PIN
|
||||
# and User PIN (sig)) with the same keys, and given only an id, OpenSSL's engine
|
||||
# matches both and logs in to neither.
|
||||
label="$(token_label)"
|
||||
[ -n "$label" ] || die "no token in slot ${slot_index} (PKCS11_SLOT_INDEX)"
|
||||
uri="pkcs11:token=$(uri_encode "$label");id=${uri_id};type=private"
|
||||
echo "hsm-sign: signing the certificate with ${uri}" >&2
|
||||
# Thirty years: the certificate's dates are not checked for APK signatures, and
|
||||
# replacing it would mean a new app identity on every device. Also long enough for
|
||||
# Google Play, which wants validity past 2033-10-22.
|
||||
OPENSSL_CONF="$work/openssl.cnf" openssl req -new -x509 -sha256 -days 10950 \
|
||||
-subj "$subject" -engine pkcs11 -keyform engine \
|
||||
-key "pkcs11:id=${uri_id};type=private" -out "$work/cert.pem"
|
||||
-key "$uri" -out "$work/cert.pem"
|
||||
openssl x509 -in "$work/cert.pem" -outform DER -out "$work/cert.der"
|
||||
if [ "$replacing" = 1 ]; then
|
||||
# Removed first, so tokens that keep several objects with one id do not end up
|
||||
|
|
|
|||
|
|
@ -51,6 +51,9 @@ fi
|
|||
export PKCS11_MODULE="$(find /usr/lib -name libsofthsm2.so | head -n 1)"
|
||||
export PKCS11_PIN=123456 KEY_ID=03
|
||||
softhsm2-util --init-token --free --label hsm-sign-test --pin "$PKCS11_PIN" --so-pin 87654321 >/dev/null
|
||||
# A second token, as the OpenPGP card shows two (User PIN and User PIN (sig)): the
|
||||
# slot the key is on has to be named, not left to whichever token matches its id.
|
||||
softhsm2-util --init-token --free --label "hsm-sign-test (sig)" --pin "$PKCS11_PIN" --so-pin 87654321 >/dev/null
|
||||
# A key and nothing else, as on the real HSM before make-cert.
|
||||
pkcs11-tool --module "$PKCS11_MODULE" --login --pin env:PKCS11_PIN \
|
||||
--keypairgen --key-type rsa:4096 --id "$KEY_ID" --label test-key >/dev/null
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue