allow using label to differentiate multiple tokens in same slot

This commit is contained in:
Emil Lerch 2026-10-04 10:37:07 -07:00
parent e4d31848fd
commit c032498244
Signed by: lobo
GPG key ID: A7B62D657EF764F8
2 changed files with 24 additions and 1 deletions

View file

@ -64,6 +64,19 @@ describe_cert() {
echo "sha256 (apk_cert_sha256): $(sha256sum "$1" | cut -d' ' -f1)"
}
# The label of the token in slot PKCS11_SLOT_INDEX, as pkcs11-tool numbers slots for
# --slot-index.
token_label() {
pkcs11-tool --module "$module" --list-slots 2>/dev/null | awk -v n="$slot_index" '
/^Slot [0-9]+ / { s = $2 }
s == n && /^[[:space:]]*token label[[:space:]]*:/ { sub(/^[^:]*:[[:space:]]*/, ""); print; exit }'
}
# $1 percent-encoded, every byte, for a pkcs11: URI (RFC 7512).
uri_encode() {
printf '%s' "$1" | od -An -v -tx1 | tr -d ' \n' | tr 'a-f' 'A-F' | sed 's/../%&/g'
}
# SunPKCS11's configuration: which library, which slot.
cat > "$work/pkcs11.cfg" <<EOF
name = HSM
@ -164,12 +177,19 @@ distinguished_name = dn
[dn]
EOF
uri_id="$(printf '%s' "$key_id" | sed 's/../%&/g')"
# The key's URI names its token: an OpenPGP card shows up as two tokens (User PIN
# and User PIN (sig)) with the same keys, and given only an id, OpenSSL's engine
# matches both and logs in to neither.
label="$(token_label)"
[ -n "$label" ] || die "no token in slot ${slot_index} (PKCS11_SLOT_INDEX)"
uri="pkcs11:token=$(uri_encode "$label");id=${uri_id};type=private"
echo "hsm-sign: signing the certificate with ${uri}" >&2
# Thirty years: the certificate's dates are not checked for APK signatures, and
# replacing it would mean a new app identity on every device. Also long enough for
# Google Play, which wants validity past 2033-10-22.
OPENSSL_CONF="$work/openssl.cnf" openssl req -new -x509 -sha256 -days 10950 \
-subj "$subject" -engine pkcs11 -keyform engine \
-key "pkcs11:id=${uri_id};type=private" -out "$work/cert.pem"
-key "$uri" -out "$work/cert.pem"
openssl x509 -in "$work/cert.pem" -outform DER -out "$work/cert.der"
if [ "$replacing" = 1 ]; then
# Removed first, so tokens that keep several objects with one id do not end up

View file

@ -51,6 +51,9 @@ fi
export PKCS11_MODULE="$(find /usr/lib -name libsofthsm2.so | head -n 1)"
export PKCS11_PIN=123456 KEY_ID=03
softhsm2-util --init-token --free --label hsm-sign-test --pin "$PKCS11_PIN" --so-pin 87654321 >/dev/null
# A second token, as the OpenPGP card shows two (User PIN and User PIN (sig)): the
# slot the key is on has to be named, not left to whichever token matches its id.
softhsm2-util --init-token --free --label "hsm-sign-test (sig)" --pin "$PKCS11_PIN" --so-pin 87654321 >/dev/null
# A key and nothing else, as on the real HSM before make-cert.
pkcs11-tool --module "$PKCS11_MODULE" --login --pin env:PKCS11_PIN \
--keypairgen --key-type rsa:4096 --id "$KEY_ID" --label test-key >/dev/null